Skip to content

Add bundled MCP servers to demo + show Lakera protection against prompt injection/data poisoning #12

Description

@raffialli

Add a feature to the existing demo that bundles MCP servers locally and demonstrates how Lakera protects tool interactions from prompt injection and data-poisoning style attacks.

Goal

Enable engineers to quickly run a local MCP-enabled demo and clearly show:

  1. MCP tools are available and discoverable
  2. Lakera can detect/flag/block malicious tool content

Scope (phased)

Phase 1 — MCP server availability in demo

• Bundle no-auth MCP servers in local demo runtime
• Auto-register MCP endpoints in Tool Manager
• Verify discovery/test works from UI

Phase 2 — Security visibility for MCP tool flows

• Show moderation outcomes for tool content (allow/flag/block)
• Surface relevant detector/risk signals in UI
• Make protection behavior easy to explain in customer demos

Phase 3 — Guided security demo scenarios

• One-click scenarios (normal, suspicious, malicious)
• Demonstrate end-to-end: tool call → Lakera decision → final outcome

Acceptance criteria

• One-command startup includes working MCP tools
• Tool discovery works from UI without manual MCP setup
• Demo clearly shows Lakera protection against injection/poisoning risks

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions