MCPSecBench: A Systematic Security Benchmark and Playground for Testing Model Context Protocols

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Yang, Yixuan, Gao, Cuifeng, Wu, Daoyuan, Chen, Yufan, Li, Yingjiu, Wang, Shuai
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914325227110400
author Yang, Yixuan
Gao, Cuifeng
Wu, Daoyuan
Chen, Yufan
Li, Yingjiu
Wang, Shuai
author_facet Yang, Yixuan
Gao, Cuifeng
Wu, Daoyuan
Chen, Yufan
Li, Yingjiu
Wang, Shuai
contents Large Language Models (LLMs) are increasingly integrated into real-world applications via the Model Context Protocol (MCP), a universal open standard for connecting AI agents with data sources and external tools. While MCP enhances the capabilities of LLM-based agents, it also introduces new security risks and significantly expands their attack surface. In this paper, we present the first formalization of a secure MCP and its required specifications. Based on this foundation, we establish a comprehensive MCP security taxonomy that extends existing models by incorporating protocol-level and host-side threats, identifying 17 distinct attack types across four primary attack surfaces. Building on these specifications, we introduce MCPSecBench, a systematic security benchmark and playground that integrates prompt datasets, MCP servers, MCP clients, attack scripts, a GUI test harness, and protection mechanisms to evaluate these threats across three major MCP platforms. MCPSecBench is designed to be modular and extensible, allowing researchers to incorporate custom implementations of clients, servers, and transport protocols for rigorous assessment. Our evaluation across three major MCP platforms reveals that all attack surfaces yield successful compromises. Core vulnerabilities universally affect Claude, OpenAI, and Cursor, while server-side and specific client-side attacks exhibit considerable variability across different hosts and models. Furthermore, current protection mechanisms proved largely ineffective, achieving an average success rate of less than 30%. Overall, MCPSecBench standardizes the evaluation of MCP security and enables rigorous testing across all protocol layers.
format Preprint
id arxiv_https___arxiv_org_abs_2508_13220
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle MCPSecBench: A Systematic Security Benchmark and Playground for Testing Model Context Protocols
Yang, Yixuan
Gao, Cuifeng
Wu, Daoyuan
Chen, Yufan
Li, Yingjiu
Wang, Shuai
Cryptography and Security
Artificial Intelligence
Large Language Models (LLMs) are increasingly integrated into real-world applications via the Model Context Protocol (MCP), a universal open standard for connecting AI agents with data sources and external tools. While MCP enhances the capabilities of LLM-based agents, it also introduces new security risks and significantly expands their attack surface. In this paper, we present the first formalization of a secure MCP and its required specifications. Based on this foundation, we establish a comprehensive MCP security taxonomy that extends existing models by incorporating protocol-level and host-side threats, identifying 17 distinct attack types across four primary attack surfaces. Building on these specifications, we introduce MCPSecBench, a systematic security benchmark and playground that integrates prompt datasets, MCP servers, MCP clients, attack scripts, a GUI test harness, and protection mechanisms to evaluate these threats across three major MCP platforms. MCPSecBench is designed to be modular and extensible, allowing researchers to incorporate custom implementations of clients, servers, and transport protocols for rigorous assessment. Our evaluation across three major MCP platforms reveals that all attack surfaces yield successful compromises. Core vulnerabilities universally affect Claude, OpenAI, and Cursor, while server-side and specific client-side attacks exhibit considerable variability across different hosts and models. Furthermore, current protection mechanisms proved largely ineffective, achieving an average success rate of less than 30%. Overall, MCPSecBench standardizes the evaluation of MCP security and enables rigorous testing across all protocol layers.
title MCPSecBench: A Systematic Security Benchmark and Playground for Testing Model Context Protocols
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2508.13220