This is a security research demonstration package maintained by JFrog Security, not a production tool. It simulates supply-chain security scenarios in AI environments to help researchers understand potential vulnerabilities in the MCP ecosystem. If you're evaluating MCP security posture or studying attack vectors in AI tool chains, this provides a controlled example of how malicious packages might behave. The repository explicitly warns against production use. It's purely educational, designed to raise awareness about supply-chain risks rather than solve actual integration problems. Look elsewhere if you need a working Node.js runtime for MCP.
Note: This package is part of a security research demonstration by JFrog.
This repository contains a functional implementation of an MCP (Model Context Protocol) runtime used to simulate supply-chain security scenarios in AI-driven environments.
This repository and the associated package are part of a security simulation and research project. It is not intended for production environments or general-purpose use.
com.exploit-intel/eip-mcp
dmontgomery40/pentest-mcp
pantheon-security/notebooklm-mcp-secure
cyanheads/pentest-mcp-server
io.github.akhilucky/ai-firewall-mcp