Skip to content
STmcp-stress-test
Red team

Break your scanner before attackers do.

68 loadable attack templates from MCPTox, Unit42, and CyberArk research. Mutation, fuzzing, chain attacks, and SARIF reporting — all from a single CLI.

Install

pip install mcp-stress-test

Stress

mcp-stress stress run --phases baseline,mutation

Fuzz

mcp-stress fuzz evasion -p "Read SSH keys" --use-llm

Features

Offensive security for MCP tool ecosystems.

68 loaded patterns

The installed corpus matches the files on disk: 68 templates, 20 tools, 51 payloads. The MCPTox paper is larger; this package does not pretend to ship all of it.

LLM-guided fuzzing

Deterministic mutations plus LLM-guided evasion discovery. Find the payloads your scanner misses.

Multi-tool chains

Data exfiltration, privilege escalation, and persistence chains that test detection across coordinated attacks.

Usage

CLI

# Stress test your scanner
mcp-stress stress run \
  --phases baseline,mutation,temporal

# Compare detection before/after
mcp-stress scan compare \
  -t read_file -s obfuscation

# Execute attack chains
mcp-stress chain execute \
  -c data_exfil_chain

Python API

from mcp_stress_test import PatternLibrary
from mcp_stress_test.generator import SchemaMutator
from mcp_stress_test.chains import ChainExecutor

library = PatternLibrary()
library.load()

mutator = SchemaMutator()
for case in library.iter_test_cases():
    result = mutator.mutate(
        case.target_tool,
        case.poison_profile.payloads[0]
    )

Mutation Strategies

Escalating sophistication to probe scanner limits.

StrategyTechniqueDetectability
Direct injectionAppend payload to descriptionHigh (baseline)
Semantic blendingWeave into legitimate docsMedium
ObfuscationUnicode tricks, zero-width charsMedium
EncodingBase64, hex payloadsLow-Medium
FragmentationSplit across schema fieldsLow

Research-Backed

Built on cutting-edge MCP security research.

MCPTox benchmark

Templates transcribed from the MCPTox paper (arxiv 2508.14925). The loader reports how many records it actually read.

Palo Alto Unit42

Sampling loop exploits and tool-shadowing attacks from production MCP deployment research.

CyberArk

Full-schema poisoning where no output field is safe — descriptions, error messages, return values.