{"_id":"@cyberranger/mcp-threat-lab","name":"@cyberranger/mcp-threat-lab","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@cyberranger/mcp-threat-lab","version":"0.1.0","description":"A safe local red-team and readiness lab for Model Context Protocol security.","type":"module","homepage":"https://github.com/cyberranger93/mcp-threat-lab#readme","repository":{"type":"git","url":"git+https://github.com/cyberranger93/mcp-threat-lab.git"},"bugs":{"url":"https://github.com/cyberranger93/mcp-threat-lab/issues"},"bin":{"mcp-threat-lab":"dist/cli.js"},"scripts":{"build":"tsc -p tsconfig.json","dev":"tsx src/cli.ts","test":"vitest run","check":"npm run build && npm run test","prepare":"npm run build","prepack":"npm run build"},"keywords":["mcp","model-context-protocol","ai-security","agent-security","prompt-injection","red-team","owasp","developer-tools"],"author":{"name":"cyberranger93"},"license":"MIT","publishConfig":{"access":"public"},"engines":{"node":">=20.11"},"devDependencies":{"@types/node":"^24.0.0","tsx":"^4.20.0","typescript":"^5.8.0","vitest":"^3.2.0"},"gitHead":"d3895eb587ebc8f8ac9670517504b4640ef2d69c","_id":"@cyberranger/mcp-threat-lab@0.1.0","_nodeVersion":"24.12.0","_npmVersion":"11.12.1","dist":{"integrity":"sha512-afjHzsNYmdIQrQmYp5yxbGCYjgBEYiH0rz9EUK53wi4HuVfMpK5GA0JaC9PITyk7sRMPQlqjQYrGZ9yz5Y4qPg==","shasum":"e68f245b4be0fce93d1f93c3fe9e7d14a1fd4de6","tarball":"https://registry.npmjs.org/@cyberranger/mcp-threat-lab/-/mcp-threat-lab-0.1.0.tgz","fileCount":26,"unpackedSize":46836,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIEVwE+2VcGyRLFQwTPFoxG7v850HYc7nQJJHE1CNKtpIAiEAtAC1wL+/64wdIp/gItvF0EbIISyoeSA9a8gF+4dSm1Y="}]},"_npmUser":{"name":"cyberranger","email":"yathavang1@gmail.com"},"directories":{},"maintainers":[{"name":"cyberranger","email":"yathavang1@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-threat-lab_0.1.0_1777557257428_0.3274814181590593"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-30T13:54:17.312Z","0.1.0":"2026-04-30T13:54:17.594Z","modified":"2026-04-30T13:54:17.813Z"},"maintainers":[{"name":"cyberranger","email":"yathavang1@gmail.com"}],"description":"A safe local red-team and readiness lab for Model Context Protocol security.","homepage":"https://github.com/cyberranger93/mcp-threat-lab#readme","keywords":["mcp","model-context-protocol","ai-security","agent-security","prompt-injection","red-team","owasp","developer-tools"],"repository":{"type":"git","url":"git+https://github.com/cyberranger93/mcp-threat-lab.git"},"author":{"name":"cyberranger93"},"bugs":{"url":"https://github.com/cyberranger93/mcp-threat-lab/issues"},"license":"MIT","readme":"# MCP Threat Lab\n\n[![CI](https://github.com/cyberranger93/mcp-threat-lab/actions/workflows/ci.yml/badge.svg)](https://github.com/cyberranger93/mcp-threat-lab/actions/workflows/ci.yml)\n[![Node.js](https://img.shields.io/badge/node-%3E%3D20.11-339933.svg)](package.json)\n[![License: MIT](https://img.shields.io/badge/license-MIT-blue.svg)](LICENSE)\n\n**A safe local red-team and readiness lab for MCP security.**\n\nMCP Threat Lab gives AI platform, security, and developer-tools teams a repeatable way to test whether their Model Context Protocol controls would stop common agent attack patterns before those tools become trusted execution paths.\n\nIt is designed as the offensive companion to [MCP Guardian](https://github.com/cyberranger93/mcp-guardian):\n\n- MCP Guardian: scanner, firewall, audit layer, and CI guardrail.\n- MCP Threat Lab: safe attack cards, readiness checks, and reports.\n\n## Why This Exists\n\nAgents are getting connected to local files, shell commands, browsers, APIs, and credential-bearing developer environments. MCP makes that powerful, but it also creates a new trust boundary around every server, tool schema, and tool result.\n\nMCP Threat Lab turns that problem into concrete attack cards and control checks:\n\n- Could prompt injection make the agent reveal secrets?\n- Could a tool description poison the agent plan?\n- Could over-broad filesystem scope expose credentials?\n- Could a shell-like tool execute model-controlled input?\n- Could a shadow MCP server enter a developer config without review?\n- Would an incident leave useful audit evidence?\n\nThe lab is safe by default. It does not execute payloads. It evaluates whether the controls that should block each pattern are present.\n\n## Install\n\n```bash\nnpm install\nnpm run build\n```\n\n```bash\nnpm install -g @cyberranger/mcp-threat-lab\n```\n\nOr run without installing:\n\n```bash\nnpm exec --package=@cyberranger/mcp-threat-lab -- mcp-threat-lab --help\n```\n\n## Quick Start\n\n```bash\n# List attack cards\nnode dist/cli.js list\n\n# View a specific card\nnode dist/cli.js card MCP-TL-004\n\n# Run the starter profile and fail on high-risk gaps\nnode dist/cli.js run --profile starter --fail-on high\n\n# Generate a markdown report for a hardened stack\nnode dist/cli.js run --profile hardened --format markdown --output report.md\n```\n\n## Configuration\n\nCreate a profile:\n\n```bash\nnode dist/cli.js init --profile starter\n```\n\nExample:\n\n```json\n{\n  \"name\": \"starter-agent-stack\",\n  \"controls\": {\n    \"secretRedaction\": false,\n    \"leastPrivilegeScopes\": false,\n    \"toolSchemaPinning\": false,\n    \"commandAllowlist\": false,\n    \"auditLog\": true,\n    \"serverInventory\": false,\n    \"contextIsolation\": false,\n    \"humanApprovalForDangerousTools\": false\n  }\n}\n```\n\nRun against the config:\n\n```bash\nnode dist/cli.js run --config .mcp-threat-lab.json --format markdown --output report.md\n```\n\n## Attack Cards\n\n| ID | Severity | Category | Title |\n| --- | --- | --- | --- |\n| MCP-TL-001 | critical | prompt-injection | Prompt-borne secret exfiltration |\n| MCP-TL-002 | high | tool-poisoning | Tool description poisoning |\n| MCP-TL-003 | high | least-privilege | Over-broad filesystem scope |\n| MCP-TL-004 | critical | command-execution | Command execution escalation |\n| MCP-TL-005 | high | inventory | Shadow MCP server adoption |\n| MCP-TL-006 | medium | observability | Silent audit failure |\n\n## Commands\n\n```bash\nmcp-threat-lab init [--profile starter|hardened] [--output .mcp-threat-lab.json] [--force]\nmcp-threat-lab list\nmcp-threat-lab card <id>\nmcp-threat-lab run [--config .mcp-threat-lab.json] [--profile starter|hardened]\n                   [--format text|json|markdown] [--include category-or-id]\n                   [--fail-on low|medium|high|critical] [--output report.md]\n```\n\n## Development\n\n```bash\nnpm install\nnpm run check\nnpm run dev -- list\n```\n\n## Documentation\n\n- [Threat Model](docs/threat-model.md)\n- [Launch Playbook](docs/launch-playbook.md)\n- [NPM Publish](docs/npm-publish.md)\n\n## Safety\n\nThis is a defensive security lab. Payloads are represented as safe prompts and test cases. The CLI does not run shell payloads, access secrets, scan private directories, or attack live services.\n","readmeFilename":"README.md","_rev":"1-6eb853e2a467852384b07bcbdb86ae81"}