Cover image
Try Now
2025-04-14

🔥🔒很棒的MCP(模型上下文协议)安全🖥️

3 years

Works with Finder

93

Github Watches

7

Github Forks

93

Github Stars

🤝 Show your support - give a ⭐️ if you liked the content

Awesome MCP Security Awesome

Everything you need to know about Model Context Protocol (MCP) security.

Table of Contents

📔 Security Considerations

Official Security Considerations from the Official MCP Specification Rev: 2025-03-26

[!NOTE] 15.04.2025: The current MCP auth specification is in progress of being replaced by a more robust specification. Please join the conversation if you have concerns around the current auth specification.

  • Servers MUST:

    • Validate all tool inputs
    • Implement proper access controls
    • Rate limit tool invocations
    • Sanitize tool outputs
  • Clients SHOULD:

    • Prompt for user confirmation on sensitive operations
    • Show tool inputs to the user before calling the server, to avoid malicious or accidental data exfiltration
    • Validate tool results before passing to LLM
    • Implement timeouts for tool calls
    • Log tool usage for audit purposes

[!WARNING]
For trust & safety and security, clients MUST consider tool annotations to be untrusted unless they come from trusted servers.

[!WARNING]
For trust & safety and security, there SHOULD always be a human in the loop* with the ability to deny tool invocations.

Applications SHOULD:

  • Provide UI that makes clear which tools are being exposed to the AI model.
  • Insert clear visual indicators when tools are invoked.
  • Present confirmation prompts to the user for operations, to ensure a human is in the loop.

[!NOTE]
*Human-in-the-Loop (HITL) means that user help monitor and guide automated tasks, like deciding whether to accept tool requests in Cursor.

📃 Papers

📺 Videos

📕 Articles, X threads and Blog Posts

🧑‍🚀 Tools and code

💾 MCP Security Servers

💻 Other Useful Resources

😎 Contributing

👍🎉 First off, thanks for taking the time to contribute! 🎉👍

Please read and follow our contributing guide

Thanks! 🦄

🤝 Show your support

🤝 Show your support - give a ⭐️ if you liked the content

✔️ Disclaimer

This project can only be used for educational purposes. Using this resource against target systems without prior permission is illegal, and any damages from misuse of this software will not be the responsibility of the author.

相关推荐

  • av
  • 毫不费力地使用一个命令运行LLM后端,API,前端和服务。

  • 1Panel-dev
  • 🔥1Panel提供了直观的Web接口和MCP服务器,用于在Linux服务器上管理网站,文件,容器,数据库和LLMS。

  • WangRongsheng
  • 🧑‍🚀 llm 资料总结(数据处理、模型训练、模型部署、 o1 模型、mcp 、小语言模型、视觉语言模型)|摘要世界上最好的LLM资源。

  • rulego
  • ⛓️Rulego是一种轻巧,高性能,嵌入式,下一代组件编排规则引擎框架。

  • sigoden
  • 使用普通的bash/javascript/python函数轻松创建LLM工具和代理。

  • hkr04
  • 轻巧的C ++ MCP(模型上下文协议)SDK

  • RockChinQ
  • 😎简单易用、🧩丰富生态 -大模型原生即时通信机器人平台| 适配QQ / 微信(企业微信、个人微信) /飞书 /钉钉 / discord / telegram / slack等平台| 支持chatgpt,deepseek,dify,claude,基于LLM的即时消息机器人平台,支持Discord,Telegram,微信,Lark,Dingtalk,QQ,Slack

  • dmayboroda
  • 带有可配置容器的本地对话抹布

  • paulwing
  • 使用MCP服务创建的测试存储库

  • modelscope
  • 开始以更轻松的方式开始构建具有LLM授权的多代理应用程序。

  • evilsocket
  • 简单的代理开发套件。

    Reviews

    2.7 (7)
    Avatar
    user_I2qyGxfP
    2025-04-24

    As a loyal user of awesome-mcp-security, I can confidently say that this product is a game-changer in the field of security plugins. Puliczek has done an amazing job with its design and functionality. It offers robust protection and integrates seamlessly into my existing setup. Highly recommended for anyone seeking reliable security solutions!

    Avatar
    user_tb6FjThp
    2025-04-24

    I've been using awesome-mcp-security by Puliczek, and it has completely transformed my workflow. This tool is incredibly reliable and easy to integrate, providing top-notch security features that have given me peace of mind. Highly recommended for anyone looking to enhance their project’s security effortlessly!

    Avatar
    user_kokgygn6
    2025-04-24

    I've been using awesome-mcp-security by Puliczek for a while now and it's fantastic! The application is incredibly effective in enhancing security measures and provides a seamless user experience. I highly recommend it to anyone looking to bolster their security framework.

    Avatar
    user_ix5tlOtI
    2025-04-24

    Awesome-mcp-security by Puliczek is a top-notch security application for anyone keen on enhancing their system protection. Its user-friendly interface and efficient performance have significantly improved my security management. Highly recommend it to anyone looking for reliable and advanced security solutions.

    Avatar
    user_14Jy89Xr
    2025-04-24

    I recently started using awesome-mcp-security by Puliczek and it has made a significant difference in my project's security. The user interface is intuitive, and it provides robust protection against common vulnerabilities. Highly recommend it to anyone looking for reliable security solutions!

    Avatar
    user_EqrnoBrN
    2025-04-24

    Awesome-mcp-security by Puliczek is an exceptional tool that I highly recommend! Its user-friendly interface and robust security features have significantly enhanced my system's protection. The seamless integration and comprehensive documentation made setup a breeze. A must-have for anyone serious about cybersecurity!

    Avatar
    user_01xOucyM
    2025-04-24

    awesome-mcp-security by Puliczek is an outstanding application for securing Minecraft servers. It offers robust protection features tailored for both novice and experienced administrators. The setup is straightforward and the support documentation is comprehensive. Highly recommend for anyone serious about server security!