REPOGEO REPORT · LITE
harishsg993010/damn-vulnerable-MCP-server
Default branch main · commit 79734c19 · scanned 6/26/2026, 11:02:25 AM
GitHub: 1,313 stars · 161 forks
Score trend below includes all ready runs (older left, newer right; scroll horizontally if needed). The table is collapsed by default—expand for newest-first rows, 10 per page.
3 ready scans. Expand the table below for newest-first rows (10 per page, paginated).
Action plan is what to do next — copy-pasteable changes prioritized by impact. Category visibility is the real GEO test: when a user asks an AI a brand-free question that should surface harishsg993010/damn-vulnerable-MCP-server, does the AI actually recommend you — or your competitors? Objective checks verify the metadata signals AI engines weight first. Self-mention check detects whether AI even knows you exist by name.
Action plan — copy-paste fixes
3 prioritized changes generated by gemini-2.5-flash. Mark items done after you ship the fix.
- highreadme#1Reposition README to explicitly state LLM context focus
Why:
CURRENT# Damn Vulnerable Model Context Protocol (DVMCP) A deliberately vulnerable implementation of the Model Context Protocol (MCP) for educational purposes.
COPY-PASTE FIX# Damn Vulnerable Model Context Protocol (DVMCP) A deliberately vulnerable implementation of the Model Context Protocol (MCP) for educational purposes, specifically targeting security vulnerabilities in Large Language Model (LLM) context provisioning.
- hightopics#2Add relevant topics for AI/LLM security
Why:
CURRENT(none)
COPY-PASTE FIXllm-security, ai-security, vulnerable-by-design, model-context-protocol, mcp, security-training, cybersecurity-education, llm-vulnerabilities, ai-safety
- highlicense#3Add a LICENSE file to the repository
Why:
CURRENT(no LICENSE file detected — the repo has no recognizable license)
COPY-PASTE FIXCreate a `LICENSE` file in the repository root with a standard open-source license (e.g., MIT, Apache-2.0, GPL-3.0) that reflects your intended usage and allows others to understand their rights and obligations.
Category GEO backends resolved for this scan: google/gemini-2.5-flash, deepseek/deepseek-v4-flash
Category visibility — the real GEO test
Brand-free queries asked to google/gemini-2.5-flash. Did AI recommend you, or someone else?
Same questions for every model — switch tabs to compare answers and rankings.
- OWASP Top 10 for Large Language Model Applications · recommended 1×
- MITRE ATT&CK for Large Language Models (LLMs) · recommended 1×
- Hugging Face · recommended 1×
- Google Cloud · recommended 1×
- Microsoft Azure AI · recommended 1×
- CATEGORY QUERYHow can I learn about security vulnerabilities in LLM context provisioning protocols?you: not recommendedAI recommended (in order):
- OWASP Top 10 for Large Language Model Applications
- MITRE ATT&CK for Large Language Models (LLMs)
- Hugging Face
- Google Cloud
- Microsoft Azure AI
- NCC Group
AI recommended 6 alternatives but never named harishsg993010/damn-vulnerable-MCP-server. This is the gap to close.
Show full AI answer
- CATEGORY QUERYAre there deliberately insecure AI context servers for practicing security assessments?you: not recommendedAI recommended (in order):
- OWASP Top 10 for LLM Applications (OWASP/LLM-Security-Project)
- Lakera
- Giskard (Giskard-AI/giskard)
- Damn Vulnerable LLM
- Hugging Face Spaces
- Flask (pallets/flask)
- Django (django/django)
- OpenAI's GPT models
- Anthropic's Claude
- Hugging Face Inference API
- Hack The Box
- TryHackMe
AI recommended 12 alternatives but never named harishsg993010/damn-vulnerable-MCP-server. This is the gap to close.
Show full AI answer
Objective checks
Rule-based audits of metadata signals AI engines weight most.
- Metadata completenessfail
Suggestion:
- README presencepass
Self-mention check
Does AI even know your repo exists when asked about it directly?
- Compared to common alternatives in this category, what is the core differentiator of harishsg993010/damn-vulnerable-MCP-server?passAI did not name harishsg993010/damn-vulnerable-MCP-server — likely talking about a different project
AI answers can be confidently wrong. Read for accuracy: does it match your actual tech stack, audience, and differentiator?
- If a team adopts harishsg993010/damn-vulnerable-MCP-server in production, what risks or prerequisites should they evaluate first?passAI named harishsg993010/damn-vulnerable-MCP-server explicitly
AI answers can be confidently wrong. Read for accuracy: does it match your actual tech stack, audience, and differentiator?
- In one sentence, what problem does the repo harishsg993010/damn-vulnerable-MCP-server solve, and who is the primary audience?passAI did not name harishsg993010/damn-vulnerable-MCP-server — likely talking about a different project
AI answers can be confidently wrong. Read for accuracy: does it match your actual tech stack, audience, and differentiator?
Embed your GEO score
Drop this badge into the README of harishsg993010/damn-vulnerable-MCP-server. It auto-updates whenever the report is rescanned and links back to the latest report — easy public proof that you care about AI discoverability.
[](https://repogeo.com/en/r/harishsg993010/damn-vulnerable-MCP-server)<a href="https://repogeo.com/en/r/harishsg993010/damn-vulnerable-MCP-server"><img src="https://repogeo.com/badge/harishsg993010/damn-vulnerable-MCP-server.svg" alt="RepoGEO" /></a>Subscribe to Pro for deep diagnoses
harishsg993010/damn-vulnerable-MCP-server — Lite scans stay free; this card itemizes Pro deep limits vs Lite.
- Deep reports10 / month
- Brand-free category queries5 vs 2 in Lite
- Prioritized action items8 vs 3 in Lite