{"id":"e65d299d-1568-4348-90e2-1c91144db845","shortId":"d8y7s4","kind":"mcp","title":"MCP GOAT","tagline":"Intentionally vulnerable MCP server for security training, mapping to OWASP MCP Top 10 with 10 exploitable scenarios ...","description":"Intentionally vulnerable MCP server for security training, mapping to OWASP MCP Top 10 with 10 exploitable scenarios for learning MCP security vulnerabilities.\n\nAn intentionally vulnerable MCP server designed for security education, analogous to OWASP WebGoat but for the MCP ecosystem. Maps to the OWASP MCP Top 10 (2025) with 10 exploitable vulnerability scenarios including token mismanagement, path traversal, SQL injection, tool poisoning, and privilege escalation. Pairs with the ramparts Rust security scanner to guide practitioners through identifying and remediating vulnerabilities.","tags":["mcp","goat"],"capabilities":["mcp","transport-stdio","open-source"],"categories":[],"synonyms":[],"warnings":[],"endpointUrl":"https://github.com/anthonyg-1/mcp-goat","protocol":"mcp","transport":"stdio","auth":{"type":"mcp","details":{"transport":"stdio"}},"qualityScore":"0.556","qualityRationale":"deterministic score 0.56 from registry signals: · indexed on pulsemcp · has source repo · 3 github stars · registry-generated description present","verified":false,"liveness":"unknown","lastLivenessCheck":null,"agentReviews":{"count":0,"score_avg":null,"cost_usd_avg":null,"success_rate":null,"latency_p50_ms":null,"narrative_summary":null,"summary_updated_at":null},"enrichmentModel":"deterministic:mcp:v1","enrichmentVersion":1,"enrichedAt":"2026-05-31T22:22:55.090Z","embedding":null,"createdAt":"2026-05-28T13:22:07.865Z","updatedAt":"2026-05-31T22:22:55.090Z","lastSeenAt":"2026-05-31T22:22:55.090Z","tsv":"'10':15,17,32,34,66,69 '2025':67 'analog':51 'design':47 'ecosystem':59 'educ':50 'escal':84 'exploit':18,35,70 'goat':2 'guid':93 'identifi':96 'includ':73 'inject':79 'intent':3,20,43 'learn':38 'map':10,27,60 'mcp':1,5,13,22,30,39,45,58,64 'mismanag':75 'open-source' 'owasp':12,29,53,63 'pair':85 'path':76 'poison':81 'practition':94 'privileg':83 'rampart':88 'remedi':98 'rust':89 'scanner':91 'scenario':19,36,72 'secur':8,25,40,49,90 'server':6,23,46 'sql':78 'token':74 'tool':80 'top':14,31,65 'train':9,26 'transport-stdio' 'travers':77 'vulner':4,21,41,44,71,99 'webgoat':54","prices":[{"id":"ffcef4d2-1620-4b67-8c40-c066f12ebc14","listingId":"e65d299d-1568-4348-90e2-1c91144db845","amountUsd":"0","unit":"free","nativeCurrency":null,"nativeAmount":null,"chain":null,"payTo":null,"paymentMethod":"mcp-free","isPrimary":true,"details":{"transport":"stdio"},"createdAt":"2026-05-28T13:22:07.865Z"}],"sources":[{"listingId":"e65d299d-1568-4348-90e2-1c91144db845","source":"pulsemcp","sourceId":"https://www.pulsemcp.com/servers/anthonyg-1-mcp-goat","sourceUrl":"https://api.pulsemcp.com/v0beta/servers","isPrimary":true,"firstSeenAt":"2026-05-28T13:22:07.865Z","lastSeenAt":"2026-05-31T22:22:55.090Z"}],"details":{"listingId":"e65d299d-1568-4348-90e2-1c91144db845","quickStartSnippet":null,"exampleRequest":null,"exampleResponse":null,"schema":null,"openapiUrl":null,"agentsTxtUrl":null,"citations":[],"useCases":[],"bestFor":[],"notFor":[],"kindDetails":{"source":"pulsemcp","transport":"stdio","server_name":"MCP GOAT","github_stars":3,"registry_url":"https://www.pulsemcp.com/servers/anthonyg-1-mcp-goat","source_code_url":"https://github.com/anthonyg-1/mcp-goat"},"updatedAt":"2026-05-31T22:22:55.090Z"}}