Automatic Red Teaming LLM-based Agents with Model Context Protocol Tools

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: He, Ping, Li, Changjiang, Zhao, Binbin, Du, Tianyu, Ji, Shouling
Format: Preprint
Publié: 2025
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866915513405276160
author He, Ping
Li, Changjiang
Zhao, Binbin
Du, Tianyu
Ji, Shouling
author_facet He, Ping
Li, Changjiang
Zhao, Binbin
Du, Tianyu
Ji, Shouling
contents The remarkable capability of large language models (LLMs) has led to the wide application of LLM-based agents in various domains. To standardize interactions between LLM-based agents and their environments, model context protocol (MCP) tools have become the de facto standard and are now widely integrated into these agents. However, the incorporation of MCP tools introduces the risk of tool poisoning attacks, which can manipulate the behavior of LLM-based agents. Although previous studies have identified such vulnerabilities, their red teaming approaches have largely remained at the proof-of-concept stage, leaving the automatic and systematic red teaming of LLM-based agents under the MCP tool poisoning paradigm an open question. To bridge this gap, we propose AutoMalTool, an automated red teaming framework for LLM-based agents by generating malicious MCP tools. Our extensive evaluation shows that AutoMalTool effectively generates malicious MCP tools capable of manipulating the behavior of mainstream LLM-based agents while evading current detection mechanisms, thereby revealing new security risks in these agents.
format Preprint
id arxiv_https___arxiv_org_abs_2509_21011
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Automatic Red Teaming LLM-based Agents with Model Context Protocol Tools
He, Ping
Li, Changjiang
Zhao, Binbin
Du, Tianyu
Ji, Shouling
Cryptography and Security
Artificial Intelligence
Software Engineering
The remarkable capability of large language models (LLMs) has led to the wide application of LLM-based agents in various domains. To standardize interactions between LLM-based agents and their environments, model context protocol (MCP) tools have become the de facto standard and are now widely integrated into these agents. However, the incorporation of MCP tools introduces the risk of tool poisoning attacks, which can manipulate the behavior of LLM-based agents. Although previous studies have identified such vulnerabilities, their red teaming approaches have largely remained at the proof-of-concept stage, leaving the automatic and systematic red teaming of LLM-based agents under the MCP tool poisoning paradigm an open question. To bridge this gap, we propose AutoMalTool, an automated red teaming framework for LLM-based agents by generating malicious MCP tools. Our extensive evaluation shows that AutoMalTool effectively generates malicious MCP tools capable of manipulating the behavior of mainstream LLM-based agents while evading current detection mechanisms, thereby revealing new security risks in these agents.
title Automatic Red Teaming LLM-based Agents with Model Context Protocol Tools
topic Cryptography and Security
Artificial Intelligence
Software Engineering
url https://arxiv.org/abs/2509.21011