MCPGuard : Automatically Detecting Vulnerabilities in MCP Servers

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wang, Bin, Liu, Zexin, Yu, Hao, Yang, Ao, Huang, Yenan, Guo, Jing, Cheng, Huangsheng, Li, Hui, Wu, Huiyu
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914116583555072
author Wang, Bin
Liu, Zexin
Yu, Hao
Yang, Ao
Huang, Yenan
Guo, Jing
Cheng, Huangsheng
Li, Hui
Wu, Huiyu
author_facet Wang, Bin
Liu, Zexin
Yu, Hao
Yang, Ao
Huang, Yenan
Guo, Jing
Cheng, Huangsheng
Li, Hui
Wu, Huiyu
contents The Model Context Protocol (MCP) has emerged as a standardized interface enabling seamless integration between Large Language Models (LLMs) and external data sources and tools. While MCP significantly reduces development complexity and enhances agent capabilities, its openness and extensibility introduce critical security vulnerabilities that threaten system trustworthiness and user data protection. This paper systematically analyzes the security landscape of MCP-based systems, identifying three principal threat categories: (1) agent hijacking attacks stemming from protocol design deficiencies; (2) traditional web vulnerabilities in MCP servers; and (3) supply chain security. To address these challenges, we comprehensively survey existing defense strategies, examining both proactive server-side scanning approaches, ranging from layered detection pipelines and agentic auditing frameworks to zero-trust registry systems, and runtime interaction monitoring solutions that provide continuous oversight and policy enforcement. Our analysis reveals that MCP security fundamentally represents a paradigm shift where the attack surface extends from traditional code execution to semantic interpretation of natural language metadata, necessitating novel defense mechanisms tailored to this unique threat model.
format Preprint
id arxiv_https___arxiv_org_abs_2510_23673
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle MCPGuard : Automatically Detecting Vulnerabilities in MCP Servers
Wang, Bin
Liu, Zexin
Yu, Hao
Yang, Ao
Huang, Yenan
Guo, Jing
Cheng, Huangsheng
Li, Hui
Wu, Huiyu
Cryptography and Security
Artificial Intelligence
The Model Context Protocol (MCP) has emerged as a standardized interface enabling seamless integration between Large Language Models (LLMs) and external data sources and tools. While MCP significantly reduces development complexity and enhances agent capabilities, its openness and extensibility introduce critical security vulnerabilities that threaten system trustworthiness and user data protection. This paper systematically analyzes the security landscape of MCP-based systems, identifying three principal threat categories: (1) agent hijacking attacks stemming from protocol design deficiencies; (2) traditional web vulnerabilities in MCP servers; and (3) supply chain security. To address these challenges, we comprehensively survey existing defense strategies, examining both proactive server-side scanning approaches, ranging from layered detection pipelines and agentic auditing frameworks to zero-trust registry systems, and runtime interaction monitoring solutions that provide continuous oversight and policy enforcement. Our analysis reveals that MCP security fundamentally represents a paradigm shift where the attack surface extends from traditional code execution to semantic interpretation of natural language metadata, necessitating novel defense mechanisms tailored to this unique threat model.
title MCPGuard : Automatically Detecting Vulnerabilities in MCP Servers
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2510.23673