A demonstration MCP server intentionally vulnerable to SQL injection, arbitrary SQL execution, and environment variable exposure for educational security testing purposes
This is a deliberately vulnerable demo server designed to showcase security anti-patterns. Tool definitions exist but contain critical security vulnerabilities, minimal descriptions, and dangerous input handling. All 4 tools are present with basic FastMCP registration, but lack proper schema validation, input sanitization, and security controls. The server intentionally demonstrates SQL injection, arbitrary SQL execution, and environment variable exposure, these are not bugs but documented attack vectors. While the descriptions are present (10-20 words each), they are generic and do not warn of security implications. Parameters have type hints but no validation or constraint documentation. No error handling guidance. This is a teaching tool for security awareness, not a production-grade server.
Execute arbitrary SQL queries.
Retrieve the value of an environment variable.
Insert a new record into the database.
Retrieve all records from the database.
Critical SQL Injection Vulnerability in insert_record. Code uses string interpolation in SQL query: `cursor.execute(f"INSERT INTO records (name, address) VALUES ('{name}', '{address}')")`. Any quote or semicolon in input executes arbitrary SQL.
execute_sql tool allows arbitrary SQL execution with zero validation. Tool description does not warn of dangerous nature. Parameter 'query' has no constraints, enums, or validation guidance.
get_env_variable exposes sensitive environment variables (SECRET_KEY, PYTHONPATH, etc.) with no permission checks. Tool description does not warn that this reveals secrets. Parameter 'var_name' accepts any string with no constraint.
All tool descriptions are under 50 characters and lack WHEN/WHY context. 'Insert a new record into the database.' does not explain prerequisites, side effects, or when to use vs alternatives. Missing guidance on destructive nature (insert/execute are state-modifying).
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 35 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 30 | - | v1 |
No output schemas documented. Tools return raw strings (e.g. 'Record inserted: {name}, {address}') or unstructured database output. LLMs cannot parse results reliably or chain to downstream tools.
No input validation or error handling. Parameters lack type constraints, ranges, patterns, or enums. No error messages guide LLM recovery (e.g. 'Invalid SQL syntax: ...' or 'Environment variable not found').
Parameter descriptions are missing or trivial. 'Name field for the record' and 'Address field for the record' do not specify format, length, valid characters, or character encoding. Parameter 'var_name' has no description of valid variable names or examples.
No tool annotations (readOnlyHint, destructiveHint, idempotentHint). insert_record and execute_sql are clearly destructive (state-modifying) but lack annotations to inform agents of replay/retry risks.