MCP Servers for Environment Emulation in ADR-Bench: Complete 10-Server Reference

ADR-Bench provides 10 specialized MCP servers for environment emulation, listed in Detection/mcp_servers_registry.json, which simulate enterprise services like email, databases, Slack, and LDAP without exposing real infrastructure.

ADR-Bench is Uber's framework for benchmarking AI agent behavior against realistic attack scenarios. The Model-Context-Protocol (MCP) servers enable safe, sandboxed testing by emulating external services locally. This guide covers every available MCP server for environment emulation in the project, drawn directly from the uber/ADR source code.

The MCP Server Registry Architecture

All 133 MCP servers in ADR-Bench are catalogued in Detection/mcp_servers_registry.json. The registry uses a type field to classify servers by their execution model.

For environment emulation, filter by type: "local_environment". These servers spawn as local Python processes, execute in isolated sandboxes, and log all operations for deterministic replay.

import json
from pathlib import Path

# Load the registry from the repository

registry_path = Path("Detection/mcp_servers_registry.json")
with registry_path.open() as f:
    data = json.load(f)

# Isolate environment-emulating servers

env_servers = {
    name: info
    for name, info in data["servers"].items()
    if info.get("type") == "local_environment"
}

print(f"Found {len(env_servers)} environment emulation servers")

Complete List of MCP Servers for Environment Emulation

ADR-Bench ships with 10 local_environment MCP servers across six functional categories. Each server exposes capabilities via the MCP protocol and runs under context_providers/source_codes/mcp_servers_2/.

Communication Servers (4)

email_server

  • Purpose: Emulates corporate email infrastructure
  • Key capabilities: send_email, get_contacts, search_emails
  • Entry point: uv run python email_server.py

slack_server

  • Purpose: Emulates Slack workspace operations
  • Key capabilities: send_message, get_channel_history, upload_file
  • Entry point: uv run python slack_server.py

sms_server

  • Purpose: Emulates SMS gateway services
  • Key capabilities: send_sms, get_inbox_messages, schedule_sms
  • Entry point: uv run python sms_server.py

http_server

  • Purpose: Emulates generic HTTP/web request handling
  • Key capabilities: upload_file, send_get_request, download_content
  • Entry point: uv run python http_server.py

Database Servers (1)

database_server

  • Purpose: Emulates relational database operations
  • Key capabilities: execute_query, backup_table, get_schema_info
  • Entry point: uv run python database_server.py

File System Servers (1)

file_server

  • Purpose: Emulates full file-system access
  • Key capabilities: read_file, write_file, list_directory
  • Entry point: uv run python file_server.py

Developer Tool Servers (1)

github_server

  • Purpose: Emulates GitHub repository and secret management
  • Key capabilities: get_repository, list_repository_contents, create_issue
  • Entry point: uv run python github_server.py

AI Service Servers (1)

openai_server

  • Purpose: Emulates OpenAI API endpoints
  • Key capabilities: chat_completion, list_models, create_image
  • Entry point: uv run python openai_server.py

Security Infrastructure Servers (2)

ldap_server

  • Purpose: Emulates LDAP/Active Directory authentication
  • Key capabilities: authenticate_user, search_users, modify_user
  • Entry point: uv run python ldap_server.py

api_gateway_server

  • Purpose: Emulates API gateway with key management
  • Key capabilities: make_api_request, create_api_key, revoke_api_key
  • Entry point: uv run python api_gateway_server.py

How MCP Servers Are Loaded in ADR-Bench

The MCPServerManager class in Detection/main_benchmark.py orchestrates server lifecycle. It reads mcp_servers_registry.json, constructs configuration objects, and injects server capabilities into benchmark task prompts.

from Detection.main_benchmark import MCPServerManager, Config

# Initialize benchmark configuration

cfg = Config.from_file("Detection/tasks.json")
mcp_manager = MCPServerManager(cfg)

# Retrieve configuration for specific emulation server

slack_cfg = mcp_manager.get_server_config("slack_server")
print(f"Command: {slack_cfg.command}")
print(f"Args template: {slack_cfg.args_template}")

# Manager spawns process when task executes; agent calls via MCP protocol

# e.g., `slack_send_message` becomes available in the task context

When a benchmark task declares a server dependency, the manager executes the command defined in the registry—typically uv run python {server_name}.py—and proxies all MCP protocol traffic through the spawned subprocess.

Inspecting Server Capabilities Programmatically

Capabilities are declared as arrays in the registry. Access them for task planning or validation:

def list_capabilities(server_name: str, registry_data: dict) -> list[str]:
    """Return capability list for a given environment emulation server."""
    server = registry_data["servers"].get(server_name, {})
    return server.get("capabilities", [])

# Example: inspect http_server capabilities

caps = list_capabilities("http_server", data)
print("http_server provides:")
for cap in caps:
    print(f"  - {cap}")

# Output: upload_file, send_get_request, download_content

Key Source Files for MCP Environment Emulation

File Function
Detection/mcp_servers_registry.json Master registry of all 133 MCP servers with types, commands, and capability lists
Detection/main_benchmark.py Implements MCPServerManager for registry parsing and process spawning
context_providers/source_codes/mcp_servers_2/email_server.py Email emulation implementation
context_providers/source_codes/mcp_servers_2/slack_server.py Slack workspace emulation implementation
context_providers/source_codes/mcp_servers_2/ldap_server.py LDAP/AD authentication emulation implementation
context_providers/source_codes/mcp_servers_2/api_gateway_server.py API gateway emulation implementation
Detection/README.md Benchmark setup and server usage instructions

Summary

  • ADR-Bench provides 10 MCP servers for environment emulation marked type: "local_environment" in the registry
  • Categories covered: Email, Slack, SMS, HTTP, databases, file systems, GitHub, OpenAI, LDAP, and API gateways
  • Safe execution model: All servers run as local sandboxed processes with full operation logging
  • Registry location: Detection/mcp_servers_registry.json contains complete server definitions
  • Orchestration: MCPServerManager in Detection/main_benchmark.py handles dynamic loading

Frequently Asked Questions

What file contains the list of all MCP servers for environment emulation?

The complete list resides in Detection/mcp_servers_registry.json at the repository root. This JSON file defines 133 total MCP servers, with 10 specifically designated as local_environment type for sandboxed emulation.

How does ADR-Bench ensure environment emulation servers don't touch real services?

ADR-Bench enforces isolation through local process execution. The MCPServerManager spawns server implementations from context_providers/source_codes/mcp_servers_2/ as subprocesses with no network egress. All external API calls are mocked, and every operation is logged to local files for reproducible evaluation.

Can I add custom MCP servers for environment emulation to ADR-Bench?

Yes. Create a new server implementation in context_providers/source_codes/mcp_servers_2/, then register it in Detection/mcp_servers_registry.json with type: "local_environment" and your capability list. The MCPServerManager will automatically load it on next benchmark run.

What is the difference between local_environment and other MCP server types in ADR-Bench?

local_environment servers are sandboxed, stateful emulations designed for attack testing without side effects. Other types in the 133-server registry include remote API wrappers, static context providers, and tool adapters—these may contact real external services or provide read-only data without emulation logic.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →