MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools
Fuente:
arXiv
Gespeichert in:
| Hauptverfasser: | Tan, Zhuoran, Hao, Run, Singer, Jeremy, Tang, Yutian, Anagnostopoulos, Christos |
|---|---|
| Format: | Preprint |
| Veröffentlicht: |
2026
|
| Schlagworte: | |
| Online-Zugang: | |
| Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Ähnliche Einträge
MCP Pitfall Lab: Exposing Developer Pitfalls in MCP Tool Server Security under Multi-Vector Attacks
von: Hao, Run, et al.
Veröffentlicht: (2026)
von: Hao, Run, et al.
Veröffentlicht: (2026)
Auditing MCP Servers for Over-Privileged Tool Capabilities
von: Huang, Charoes, et al.
Veröffentlicht: (2026)
von: Huang, Charoes, et al.
Veröffentlicht: (2026)
Operational Runtime Behavior Mining for Open-Source Supply Chain Security
von: Tan, Zhuoran, et al.
Veröffentlicht: (2026)
von: Tan, Zhuoran, et al.
Veröffentlicht: (2026)
When MCP Servers Attack: Taxonomy, Feasibility, and Mitigation
von: Zhao, Weibo, et al.
Veröffentlicht: (2025)
von: Zhao, Weibo, et al.
Veröffentlicht: (2025)
Beyond the Protocol: Unveiling Attack Vectors in the Model Context Protocol (MCP) Ecosystem
von: Song, Hao, et al.
Veröffentlicht: (2025)
von: Song, Hao, et al.
Veröffentlicht: (2025)
We Urgently Need Privilege Management in MCP: A Measurement of API Usage in MCP Ecosystems
von: Li, Zhihao, et al.
Veröffentlicht: (2025)
von: Li, Zhihao, et al.
Veröffentlicht: (2025)
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers
von: Huang, Yiheng, et al.
Veröffentlicht: (2026)
von: Huang, Yiheng, et al.
Veröffentlicht: (2026)
WACANA: A Concolic Analyzer for Detecting On-chain Data Vulnerabilities in WASM Smart Contracts
von: Wang, Wansen, et al.
Veröffentlicht: (2024)
von: Wang, Wansen, et al.
Veröffentlicht: (2024)
Options, Not Clicks: Lattice Refinement for Consent-Driven MCP Authorization
von: Li, Ying, et al.
Veröffentlicht: (2026)
von: Li, Ying, et al.
Veröffentlicht: (2026)
Threadbox: Sandboxing for Modular Security
von: Alhindi, Maysara, et al.
Veröffentlicht: (2025)
von: Alhindi, Maysara, et al.
Veröffentlicht: (2025)
SandCell: Sandboxing Rust Beyond Unsafe Code
von: Zhang, Jialun, et al.
Veröffentlicht: (2025)
von: Zhang, Jialun, et al.
Veröffentlicht: (2025)
Attesting LLM Pipelines: Enforcing Verifiable Training and Release Claims
von: Tan, Zhuoran, et al.
Veröffentlicht: (2026)
von: Tan, Zhuoran, et al.
Veröffentlicht: (2026)
Comparing Effectiveness and Efficiency of Interactive Application Security Testing (IAST) and Runtime Application Self-Protection (RASP) Tools in a Large Java-based System
von: Seth, Aishwarya, et al.
Veröffentlicht: (2023)
von: Seth, Aishwarya, et al.
Veröffentlicht: (2023)
ARAP: Demystifying Anti Runtime Analysis Code in Android Apps
von: Suo, Dewen, et al.
Veröffentlicht: (2024)
von: Suo, Dewen, et al.
Veröffentlicht: (2024)
Sandboxing Adoption in Open Source Ecosystems
von: Alhindi, Maysara, et al.
Veröffentlicht: (2024)
von: Alhindi, Maysara, et al.
Veröffentlicht: (2024)
KEENHash: Hashing Programs into Function-Aware Embeddings for Large-Scale Binary Code Similarity Analysis
von: Liu, Zhijie, et al.
Veröffentlicht: (2025)
von: Liu, Zhijie, et al.
Veröffentlicht: (2025)
From Obfuscated to Obvious: A Comprehensive JavaScript Deobfuscation Tool for Security Analysis
von: Zhou, Dongchao, et al.
Veröffentlicht: (2025)
von: Zhou, Dongchao, et al.
Veröffentlicht: (2025)
Distributed Temporal Graph Learning with Provenance for APT Detection in Supply Chains
von: Tan, Zhuoran, et al.
Veröffentlicht: (2025)
von: Tan, Zhuoran, et al.
Veröffentlicht: (2025)
Static Security Vulnerability Scanning of Proprietary and Open-Source Software: An Adaptable Process with Variants and Results
von: Cusick, James J.
Veröffentlicht: (2025)
von: Cusick, James J.
Veröffentlicht: (2025)
Classport: Designing Runtime Dependency Introspection for Java
von: Cofano, Serena, et al.
Veröffentlicht: (2025)
von: Cofano, Serena, et al.
Veröffentlicht: (2025)
OSPtrack: A Labeled Dataset Targeting Simulated Execution of Open-Source Software
von: Tan, Zhuoran, et al.
Veröffentlicht: (2024)
von: Tan, Zhuoran, et al.
Veröffentlicht: (2024)
Improving Smart Contract Security with Contrastive Learning-based Vulnerability Detection
von: Chen, Yizhou, et al.
Veröffentlicht: (2024)
von: Chen, Yizhou, et al.
Veröffentlicht: (2024)
Guiding Symbolic Execution with Static Analysis and LLMs for Vulnerability Discovery
von: Shafiuzzaman, Md, et al.
Veröffentlicht: (2026)
von: Shafiuzzaman, Md, et al.
Veröffentlicht: (2026)
SmartOracle: Generating Smart Contract Oracle via Fine-Grained Invariant Detection
von: Su, Jianzhong, et al.
Veröffentlicht: (2024)
von: Su, Jianzhong, et al.
Veröffentlicht: (2024)
Smart Contract and DeFi Security Tools: Do They Meet the Needs of Practitioners?
von: Chaliasos, Stefanos, et al.
Veröffentlicht: (2023)
von: Chaliasos, Stefanos, et al.
Veröffentlicht: (2023)
Fakeium: A Dynamic Execution Environment for JavaScript Program Analysis
von: Moreno, José Miguel, et al.
Veröffentlicht: (2024)
von: Moreno, José Miguel, et al.
Veröffentlicht: (2024)
Security study based on the Chatgptplugin system: ldentifying Security Vulnerabilities
von: Ren, Ruomai
Veröffentlicht: (2025)
von: Ren, Ruomai
Veröffentlicht: (2025)
LLMs as Firmware Experts: A Runtime-Grown Tree-of-Agents Framework
von: Zhang, Xiangrui, et al.
Veröffentlicht: (2025)
von: Zhang, Xiangrui, et al.
Veröffentlicht: (2025)
Many Tools, Few Exploitable Vulnerabilities: A Survey of 246 Static Code Analyzers for Security
von: Hermann, Kevin, et al.
Veröffentlicht: (2026)
von: Hermann, Kevin, et al.
Veröffentlicht: (2026)
SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
von: Okafor, Chinenye, et al.
Veröffentlicht: (2024)
von: Okafor, Chinenye, et al.
Veröffentlicht: (2024)
GoLeash: Mitigating Golang Software Supply Chain Attacks with Runtime Policy Enforcement
von: Cesarano, Carmine, et al.
Veröffentlicht: (2025)
von: Cesarano, Carmine, et al.
Veröffentlicht: (2025)
Synergistic Directed Execution and LLM-Driven Analysis for Zero-Day AI-Generated Malware Detection
von: Edwards, George, et al.
Veröffentlicht: (2026)
von: Edwards, George, et al.
Veröffentlicht: (2026)
Machine Learning-Based Detection of MCP Attacks
von: Mattsson, Tobias, et al.
Veröffentlicht: (2026)
von: Mattsson, Tobias, et al.
Veröffentlicht: (2026)
SBOM Generation Tools in the Python Ecosystem: an In-Detail Analysis
von: Cofano, Serena, et al.
Veröffentlicht: (2024)
von: Cofano, Serena, et al.
Veröffentlicht: (2024)
Exploring the Security Threats of Retriever Backdoors in Retrieval-Augmented Code Generation
von: Li, Tian, et al.
Veröffentlicht: (2025)
von: Li, Tian, et al.
Veröffentlicht: (2025)
"False negative -- that one is going to kill you": Understanding Industry Perspectives of Static Analysis based Security Testing
von: Ami, Amit Seal, et al.
Veröffentlicht: (2023)
von: Ami, Amit Seal, et al.
Veröffentlicht: (2023)
Artemis: Toward Accurate Detection of Server-Side Request Forgeries through LLM-Assisted Inter-Procedural Path-Sensitive Taint Analysis
von: Ji, Yuchen, et al.
Veröffentlicht: (2025)
von: Ji, Yuchen, et al.
Veröffentlicht: (2025)
An Empirical Analysis of EOS Blockchain: Architecture, Contract, and Security
von: Liu, Haiyang, et al.
Veröffentlicht: (2025)
von: Liu, Haiyang, et al.
Veröffentlicht: (2025)
ColorGo: Directed Concolic Execution
von: Li, Jia, et al.
Veröffentlicht: (2025)
von: Li, Jia, et al.
Veröffentlicht: (2025)
SAGA: Detecting Security Vulnerabilities Using Static Aspect Analysis
von: Marquer, Yoann, et al.
Veröffentlicht: (2026)
von: Marquer, Yoann, et al.
Veröffentlicht: (2026)
Ähnliche Einträge
-
MCP Pitfall Lab: Exposing Developer Pitfalls in MCP Tool Server Security under Multi-Vector Attacks
von: Hao, Run, et al.
Veröffentlicht: (2026) -
Auditing MCP Servers for Over-Privileged Tool Capabilities
von: Huang, Charoes, et al.
Veröffentlicht: (2026) -
Operational Runtime Behavior Mining for Open-Source Supply Chain Security
von: Tan, Zhuoran, et al.
Veröffentlicht: (2026) -
When MCP Servers Attack: Taxonomy, Feasibility, and Mitigation
von: Zhao, Weibo, et al.
Veröffentlicht: (2025) -
Beyond the Protocol: Unveiling Attack Vectors in the Model Context Protocol (MCP) Ecosystem
von: Song, Hao, et al.
Veröffentlicht: (2025)