mcp server
mcp
Personalised developer security learning pathways from SecDim's challenges and courses.
Description as published by the maintainer. Source
- version 1.0.1
- active
- security
active — Most recent push to the repository was 2026-07-20. Dashed tags are derived by ZBS Index from the published description, not stated by the maintainer.
What this server can do
7 functions, named and described by the server itself. Parameter names are shown because they say more about what a function does than its name usually does.
fetch(id)- Fetch detailed content for a specific SecDim Play lab (hands-on, scored challenge). Args: id: Lab ID in format "lab:slug" (e.g., "lab:xss-dom") Returns: Dictionary containing: - id: The lab ID - title: Lab title - content: Detailed content in markdown format - metadata: Additional lab information Required: id.
get_learn_course(course_slug)- Get a SecDim Learn course's details, including its syllabus of topics. Args: course_slug: The course's slug, as returned by search_learn_courses (e.g. "owasp-top-10") Returns: Dictionary with the course's title, description, image, slug, "difficulty" label and a "topics" list. Each topic includes its title, description, category, slug, kind (e.g. text/video/lab), level, subscription tier, duration and completion status. Use get_learn_topic with the course slug and a topic's slug to view its content. Required: course_slug.
get_learn_topic(topic_slug, course_slug)- Get a SecDim Learn topic's content. Args: course_slug: The course's slug, as returned by search_learn_courses (e.g. "owasp-top-10") topic_slug: The topic's slug, as returned by get_learn_course (e.g. "introduction-secure-coding") Returns: Dictionary with the topic's title, description, category, kind, level, subscription tier, duration, completion status and "file_content" (the topic's content in AsciiDoc format). If the topic requires a SecDim Learn subscription that the current account does not have, an "error" explaining this is returned instead. Required: course_slug, topic_slug.
get_secdim_profile(secdim_username)- Fetch a SecDim player's profile: scores, completed challenges, skills, security interests and an experience estimate. Use this tool to understand a player's demonstrated secure coding ability before building a learning pathway. The profile includes actual challenge completion data (by difficulty level) and security topics the player has practised — weight this demonstrated performance over a user's self-reported level when deciding what difficulty and topics to recommend. The 'guidance' field provides a ready-to-use summary of what difficulty and topics to target next, and whether the player is new, intermediate or experienced. Args: secdim_username: The player's SecDim username (e.g. "alice") Returns: Dictionary with scores, challenges_solved breakdown, skills (languages and technologies), completed_challenges list, security_interests, experience_estimate and guidance. If the user doesn't exist or an error occurs, returns an error dict. Required: secdim_username.
search(query)- Search for SecDim Play secure coding labs (hands-on, scored challenges). This tool searches across SecDim Play's hands-on secure coding labs based on the search query. The backend API handles parsing of vulnerability names, CWE IDs, and OWASP IDs. Language can be specified using the format "lang:javascript". Args: query: Search query that may include: - Vulnerability names (e.g., "XSS", "SQL injection") - CWE IDs (e.g., "79") - OWASP IDs (e.g., "A03:2021") Examples: - "XSS lang:javascript" - searches for XSS labs in JavaScript - "SQL injection lang:Python" - searches for SQL injection labs in Python - "79" - searches for labs related to CWE-79 Returns: Dictionary with search results containing: - results: List of matching SecDim Play labs with id, title, snippet, and metadata Required: query.
search_learn_courses(search)- Search SecDim Learn courses. SecDim Learn provides tutorial-based courses (mixing video, text and hands-on lab topics) covering secure coding, secure design, vibe coding security, devsecops, and cloud security. Many courses are complementary or prerequisite to hands-on, scored SecDim Play challenges/labs. Use this tool to: - Browse the SecDim Learn course catalogue - Find courses related to a topic, language, or technology (e.g. "OWASP Top 10", "fuzzing", "Python") Args: search: Optional search term to filter courses by title, description, or tags. If omitted, returns the full course catalogue. Returns: Dictionary with a "courses" list. Each course includes its title, description, image, slug, tags, numeric "level" (1=beginner, 2=intermediate, 3=advanced) and a "difficulty" label. Use get_learn_course with a course's slug to view its syllabus of topics.
search_play_challenges(cwe, type, mitre, owasp, search, language, difficulty, technology)- Return a list of hands-on SecDim Play secure coding challenges (labs) related to a detected or suspected vulnerability. SecDim Play challenges are scored, hands-on labs: find and fix a real vulnerability in running code to earn points and badges. Use this tool to: - Find hands-on SecDim Play labs for specific vulnerabilities like XSS, SQL Injection, etc. - Explore OWASP Top 10 vulnerabilities and related labs - Provide additional resources and guides to help developers improve their secure coding skills For structured tutorial content (text, video, and lab-based courses) on the same vulnerability, use search_learn_courses (SecDim Learn) instead or in addition. Args: search: Search term for the vulnerability (e.g., 'xss', 'sql-injection', 'injection') cwe: Common Weakness Enumeration (CWE) ID to filter by owasp: OWASP category to filter by (e.g., 'a03:2021') technology: Technology or framework to filter by (e.g., 'react', 'django') language: Programming language to filter by (e.g., 'javascript', 'python') difficulty: Difficulty level to filter by (e.g., 'trivial', 'easy', 'medium', 'hard') type: Challenge format to filter by (e.g., 'battle', 'exploitation', 'incident-response') mitre: MITRE ATT&CK ID to filter by (e.g., 'T1102.003') SecDim Play challenges (labs) each simulate a real vulnerability. They are scored according to the following difficulty levels: - Trivial: Easy to find and path vulnerabilities. It can be completed in 5-10 minutes. 1-15 points. - Easy: Known vulnerabilities. It can be completed in 10-30 minutes. 16-35 points. - Medium: Known vulnerabilities but require defence-in-depth patch. It can be completed in 20-30 minutes. 36-70 points. - Hard: Hard to find or patch vulnerabilities. It can be completed in 30-60 minutes. 71-100 points. - Battle: SecDim Flagship attack and defence challenge that require both vulnerability exploitation and mitigation skills. Points are accumulated. Returns: Dictionary containing SecDim Play labs results or error If there are no results, user can perform a manual search on the SecDim Play frontend (SECDIM_PLAY_FRONTEND_BASE_URL) Required: search.
Last successful function declaration observed on . Source: https://mcp.secdim.com/mcp. We list what the server declared; we do not call any of these functions.
Endpoint status observed on . Source: https://mcp.secdim.com/mcp.
Signals
These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.
| Signal | Value | What it measures | Window | Observed | Source |
|---|---|---|---|---|---|
| GitHub stars | 0 | Number of GitHub accounts that bookmarked this repository since it was created. It is a bookmark count, not installs, not active users and not quality. | cumulative, all time | GitHub | |
| Last commit | 2026-07-20 | Date of the most recent push to any branch. This is the strongest cheap indicator of whether the project is still maintained. | point in time | GitHub | |
| Open issues | 0 | Open issues plus open pull requests, as GitHub counts them together. A high number can mean an active project or an abandoned one. | as of fetch | GitHub | |
| Latest published version | 1.0.1 | Latest version string the maintainer published to the registry. | as of fetch | Model Context Protocol | |
| Registry record last updated | 2026-07-20 | When the registry record was last updated by its maintainer. | point in time | Model Context Protocol | |
| First listed in the MCP Registry | 2026-07-20 | Date this server was first published to the official MCP Registry. Not a usage or quality measure. | point in time | Model Context Protocol | |
| repository status | active | The repository exists on GitHub and is not archived. This says nothing about how recently it was worked on. | as of fetch | GitHub | |
| mcp tools declared | 7 tools | Number of functions the server itself declared when asked to list them. This is what the server offers an agent, not a measure of how well any of them work. | as of probe | mcp.secdim.com | |
| mcp endpoint status | ok | The server listed 7 functions when asked. | as of probe | mcp.secdim.com |
Where to get it
Related, by what their authors tagged them
-
TrainTools
— last commit 2026-07-22, shares training
Recommend paper-backed diagnostics for PyTorch and Hugging Face training problems.
-
AgentTrust — Identity & Trust for A2A Agents
— last commit 2026-04-09, shares security
Identity, trust, and A2A orchestration for autonomous AI agents. Official A2A partner.
-
ai.kernora/agent-sec
— last commit 2026-07-31, shares security
Zero-install security baseline for AI coding agents — OWASP/CWE-cited rules over MCP.
-
ai.radmail/radmail-mcp
— last commit 2026-07-04, shares security
Email OS for agents - real-inbox search, triage, commitments, and a verifiable BEC hard-stop.
-
Scry
— archived, last commit 2026-05-25, shares security
Free IPv4 lookups against a distributed attacker-observation corpus.
-
app.scfcontrolsplatform/mcp-server-scf
— last commit 2026-07-27, shares security
MCP server for the SCF Controls Platform — 83 tools for controls, evidence, risk, and TPRM.
-
Arcjet
— last commit 2026-04-09, shares security
An MCP server for Arcjet - the runtime security platform that ships with your AI code.
-
ContrastAPI
— last commit 2026-08-04, shares security
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
-
com.datakoot/security-intel-mcp
— last commit 2026-08-02, shares security
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
-
com.fidacy/ai-agent-firewall
— last commit 2026-08-04, shares security
Every agent action watched, every money-moving one gated, every verdict independently verifiable.
These share tags the maintainers applied themselves, such as training, security. Common tags like "mcp" or "ai" are ignored for this: agreeing with six hundred other projects is not a similarity.
This is not a recommendation and not a test result. It is a map of what the authors said their work is about.
How the author describes it
Topics the maintainer set on GitHub: mcp-server, security, training.
This record as data
Every field on this page, with its source and observation date, is in the catalog JSON. Fetch the whole kind at once instead of parsing this HTML.
GET /api/v1/entries/mcp_server.json