A set of deliberately vulnerable MCP servers (injection sinks, exfiltration tools, over-broad tool schemas, PII leaks), each labeled, plus a metrics harness that runs any scanner against the corpus and prints a detection-rate scorecard.
**An open-source evaluation corpus and benchmark harness for MCP security.** > The MCP security ecosystem has plenty of scanners and no shared testbed. This is the testbed. Eleven deliberately vulnerable MCP servers, 14 labeled exploitable weaknesses across 8 threat categories, 3 benign controls for false-positive measurement, and