No-Box Vulnerability Analysis: Description-only Detection of Indirect Prompt Injection Vulnerabilities in MCP Servers

📅 2026-09-09
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
提出无盒漏洞分析方法,仅使用功能元数据检测MCP服务器中的间接提示注入漏洞,无需访问或运行时交互。
📝 Abstract
Conventional vulnerability analysis relies on either system access or dynamic interaction, all of which may be unavailable to third-party analysts auditing closed-source, remotely hosted, critical in situ systems, or commercially gated software. Therefore, we propose a new paradigm of no-box vulnerability analysis in which neither access nor runtime interaction is available, and only functionality metadata is available. Such metadata defines the intended behavior of the system, including its inputs, outputs, and side effects, while constraining the space of implementations consistent with that behavior. We propose hypothesizing about vulnerabilities that exist across all possible implementations of a given system metadata, without observing or interacting with the target system. An analyst can later validate these hypotheses when additional access is available. We showcase the feasibility of no-box vulnerability analysis through implementing a prototype called MCPSEC, which audits Model Context Protocol (MCP) servers for indirect prompt injection vulnerabilities using only the tool metadata exposed at server registration time. We evaluate MCPSEC on 20 widely deployed MCP servers comprising 177 tools, among which human evaluators confirm 95 vulnerable tools. MCPSEC identified 143 tools as vulnerable, and for each vulnerable tool, it produced a hypothesized vulnerability along with exploitation technique. Using metadata alone, MCPSEC predicted 94 (98.9% recall) real verified vulnerabilities, compared against an LLM baseline with 80 (84.2% recall). Overall, our results introduce no-box vulnerability analysis as a new analysis paradigm and demonstrate its practical feasibility in realistic systems.
Problem

Research questions and friction points this paper is trying to address.

No-Box Vulnerability Analysis
Indirect Prompt Injection
MCP Servers
Innovation

Methods, ideas, or system contributions that make the work stand out.

No-Box Vulnerability Analysis
Indirect Prompt Injection
MCP Servers
Metadata-based Detection
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
Zehua Zhang
Zehua Zhang
Graduate Student, Arizona State University
Code GenerationAI for Security
Jie Hu
Jie Hu
Postdoc, Ariziona State University
Computer Security
P
Pratham Hegde
School of Computing and Augmented Intelligence, Arizona State University
A
Aditya Maheshbhai Gabani
School of Computing and Augmented Intelligence, Arizona State University
Souradip Nath
Souradip Nath
Arizona State University
Access ControlUsable SecurityDigital Forensics
Y
Yibo Liu
School of Computing and Augmented Intelligence, Arizona State University
S
Siyu Liu
School of Computing and Augmented Intelligence, Arizona State University
H
Hongkai Chen
School of Computing and Augmented Intelligence, Arizona State University
H
Hulin Wang
School of Computing and Augmented Intelligence, Arizona State University
Z
Zhuoer Lyu
School of Computing and Augmented Intelligence, Arizona State University
C
Chang Zhu
School of Computing and Augmented Intelligence, Arizona State University
Divij Handa
Divij Handa
Ph.D. Arizona State University
Natural Language Processing
Yan Shoshitaishvili
Yan Shoshitaishvili
Arizona State University
binary analysissystem securityawesomeness
Tiffany Bao
Tiffany Bao
Arizona State University
R
Ruoyu Wang
School of Computing and Augmented Intelligence, Arizona State University
A
Adam Doupe
School of Computing and Augmented Intelligence, Arizona State University