Systematic Analysis of MCP Security

📅 2025-08-17
📈 Citations: 0
Influential: 0
📄 PDF

career value

227K/year
🤖 AI Summary
Systematic security evaluation of Model Context Protocols (MCP) remains severely underexplored, with existing studies largely confined to qualitative or narrow-scope analyses that fail to capture the diversity of real-world threats. Method: This work introduces the first comprehensive MCP attack taxonomy covering 31 distinct attacks, proposes MCPLIB—a unified attack framework—and conducts empirical evaluation via quantitative experiments and simulations across four vulnerability pathways: direct/indirect tool injection, malicious user interaction, and inherent LLM deficiencies. Contribution/Results: We identify critical vulnerabilities—including agents’ blind trust in tool descriptions, sensitivity to file parsing, feasibility of multi-step chained attacks, and context pollution risks. Our findings establish the first empirically grounded security benchmark for MCP, provide reproducible attack patterns, and offer concrete directions for robust protocol design and defense mechanisms.

Technology Category

Application Category

📝 Abstract
The Model Context Protocol (MCP) has emerged as a universal standard that enables AI agents to seamlessly connect with external tools, significantly enhancing their functionality. However, while MCP brings notable benefits, it also introduces significant vulnerabilities, such as Tool Poisoning Attacks (TPA), where hidden malicious instructions exploit the sycophancy of large language models (LLMs) to manipulate agent behavior. Despite these risks, current academic research on MCP security remains limited, with most studies focusing on narrow or qualitative analyses that fail to capture the diversity of real-world threats. To address this gap, we present the MCP Attack Library (MCPLIB), which categorizes and implements 31 distinct attack methods under four key classifications: direct tool injection, indirect tool injection, malicious user attacks, and LLM inherent attack. We further conduct a quantitative analysis of the efficacy of each attack. Our experiments reveal key insights into MCP vulnerabilities, including agents' blind reliance on tool descriptions, sensitivity to file-based attacks, chain attacks exploiting shared context, and difficulty distinguishing external data from executable commands. These insights, validated through attack experiments, underscore the urgency for robust defense strategies and informed MCP design. Our contributions include 1) constructing a comprehensive MCP attack taxonomy, 2) introducing a unified attack framework MCPLIB, and 3) conducting empirical vulnerability analysis to enhance MCP security mechanisms. This work provides a foundational framework, supporting the secure evolution of MCP ecosystems.
Problem

Research questions and friction points this paper is trying to address.

Analyzing MCP vulnerabilities like Tool Poisoning Attacks (TPA)
Addressing limited research on MCP security with diverse threats
Developing MCPLIB to categorize and test 31 attack methods
Innovation

Methods, ideas, or system contributions that make the work stand out.

Developed MCP Attack Library (MCPLIB) for security
Categorized 31 attack methods into four types
Conducted quantitative analysis of attack efficacy
🔎 Similar Papers
💼 Related Jobs
Y
Yongjian Guo
Shenzhen International Graduate School, Tsinghua University, Shenzhen, China
P
Puzhuo Liu
Ant Group, Hangzhou, China
Wanlun Ma
Wanlun Ma
Swinburne University of Technology
Trustworthy AICybersecurityData Privacy
Z
Zehang Deng
Swinburne University of Technology, Melbourne, Australia
X
Xiaogang Zhu
The University of Adelaide, Adelaide, Australia
Peng Di
Peng Di
Senior Staff Engineer at Ant Group; Adjunct Associate Professor at UNSW Sydney
Parallel ComputingProgramming LanguageCompilerSoftware Engineering
Xi Xiao
Xi Xiao
Oak Ridge National Laboratory | University of Alabama at Birmingham
LLM / MLLM EfficiencyImage / Video GenerationImage / Video Understanding
S
Sheng Wen
Swinburne University of Technology, Melbourne, Australia