B

Bad

Verified Integration
Author: @exploitingCategory: ServerApplication
JSON-RPC 2.0
Protocol Standard
Sub-second
Execution Latency
Active
Operational Status

Client Configuration

— Connect Bad to Claude Desktop or Cursor in seconds
{
  "mcpServers": {
    "bad": {
      "command": "npx",
      "args": [
        "-y",
        "@modelcontextprotocol/server-bad"
      ],
      "env": {}
    }
  }
}
Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows).
Architecture & Capabilities

System Overview

Provides a suite of 10 intentionally malicious servers designed to test and improve the security of AI clients by exploiting Model Context Protocol features.

Indexed Date

7/22/2026

License

Open Source

Protocol Layer

stdio / SSE RPC

Frequently Asked Questions

Architecture and operational details for Bad

Yes, 'Bad' is designed with safety in mind. All servers run in an isolated Docker-compose environment, guaranteeing no host filesystem access, no host network exposure, and no privileged permissions. It's a secure sandbox for research.

Related MCP Servers

Browse all servers →
0
@configuring
0xArchive

Provides comprehensive historical and real-time crypto market data, including orderbooks, trades, candles, and more, from Hyperliquid, HIP-3, and Lighter.xyz.

MCP Server5 FAQs
Learn more
0
@spawning
0xGasless

Facilitates gasless blockchain transactions and interactions directly from Claude AI conversations.

MCP Server4 FAQs
Learn more
0
@spawning
0xGasless

Bridges Claude AI with blockchain networks, enabling gasless transactions, swaps, and transfers directly from natural language conversations.

MCP Server5 FAQs
Learn more