MCP-ITP: An Automated Framework for Implicit Tool Poisoning in MCP
Fuente:
arXiv
Saved in:
| Main Authors: | Li, Ruiqi, Wang, Zhiqiang, Yao, Yunhao, Li, Xiang-Yang |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
MCP-in-SoS: Risk assessment framework for open-source MCP servers
by: Kumar, Pratyay, et al.
Published: (2026)
by: Kumar, Pratyay, et al.
Published: (2026)
When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents
by: Liu, Shi, et al.
Published: (2026)
by: Liu, Shi, et al.
Published: (2026)
MCPGuard : Automatically Detecting Vulnerabilities in MCP Servers
by: Wang, Bin, et al.
Published: (2025)
by: Wang, Bin, et al.
Published: (2025)
MCP Guardian: A Security-First Layer for Safeguarding MCP-Based AI System
by: Kumar, Sonu, et al.
Published: (2025)
by: Kumar, Sonu, et al.
Published: (2025)
We Urgently Need Privilege Management in MCP: A Measurement of API Usage in MCP Ecosystems
by: Li, Zhihao, et al.
Published: (2025)
by: Li, Zhihao, et al.
Published: (2025)
Don't believe everything you read: Understanding and Measuring MCP Behavior under Misleading Tool Descriptions
by: Li, Zhihao, et al.
Published: (2026)
by: Li, Zhihao, et al.
Published: (2026)
Secure Tool Manifest and Digital Signing Solution for Verifiable MCP and LLM Pipelines
by: Jamshidi, Saeid, et al.
Published: (2026)
by: Jamshidi, Saeid, et al.
Published: (2026)
From Tool Orchestration to Code Execution: A Study of MCP Design Choices
by: Felendler, Yuval, et al.
Published: (2026)
by: Felendler, Yuval, et al.
Published: (2026)
Prompts Don't Protect: Architectural Enforcement via MCP Proxy for LLM Tool Access Control
by: Uppala, Rohith
Published: (2026)
by: Uppala, Rohith
Published: (2026)
Trivial Trojans: How Minimal MCP Servers Enable Cross-Tool Exfiltration of Sensitive Data
by: Croce, Nicola, et al.
Published: (2025)
by: Croce, Nicola, et al.
Published: (2025)
MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
by: Wang, Zhiqiang, et al.
Published: (2025)
by: Wang, Zhiqiang, et al.
Published: (2025)
Enterprise-Grade Security for the Model Context Protocol (MCP): Frameworks and Mitigation Strategies
by: Narajala, Vineeth Sai, et al.
Published: (2025)
by: Narajala, Vineeth Sai, et al.
Published: (2025)
PentestMCP: A Toolkit for Agentic Penetration Testing
by: Ezetta, Zachary, et al.
Published: (2025)
by: Ezetta, Zachary, et al.
Published: (2025)
Simplified and Secure MCP Gateways for Enterprise AI Integration
by: Brett, Ivo
Published: (2025)
by: Brett, Ivo
Published: (2025)
Compatibility at a Cost: Systematic Discovery and Exploitation of MCP Clause-Compliance Vulnerabilities
by: Yang, Nanzi, et al.
Published: (2026)
by: Yang, Nanzi, et al.
Published: (2026)
Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions
by: Hou, Xinyi, et al.
Published: (2025)
by: Hou, Xinyi, et al.
Published: (2025)
MCP Security Bench (MSB): Benchmarking Attacks Against Model Context Protocol in LLM Agents
by: Zhang, Dongsen, et al.
Published: (2025)
by: Zhang, Dongsen, et al.
Published: (2025)
MCP-Guard: A Multi-Stage Defense-in-Depth Framework for Securing Model Context Protocol in Agentic AI
by: Xing, Wenpeng, et al.
Published: (2025)
by: Xing, Wenpeng, et al.
Published: (2025)
Options, Not Clicks: Lattice Refinement for Consent-Driven MCP Authorization
by: Li, Ying, et al.
Published: (2026)
by: Li, Ying, et al.
Published: (2026)
A Formal Security Framework for MCP-Based AI Agents: Threat Taxonomy, Verification Models, and Defense Mechanisms
by: Acharya, Nirajan, et al.
Published: (2026)
by: Acharya, Nirajan, et al.
Published: (2026)
Governed MCP: Kernel-Level Tool Governance for AI Agents via Logit-Based Safety Primitives
by: Son, Daeyeon
Published: (2026)
by: Son, Daeyeon
Published: (2026)
CASCADE: A Cascaded Hybrid Defense Architecture for Prompt Injection Detection in MCP-Based Systems
by: Turgut, İpek Abasıkeleş, et al.
Published: (2026)
by: Turgut, İpek Abasıkeleş, et al.
Published: (2026)
MCP-DPT: A Defense-Placement Taxonomy and Coverage Analysis for Model Context Protocol Security
by: Rostamzadeh, Mehrdad, et al.
Published: (2026)
by: Rostamzadeh, Mehrdad, et al.
Published: (2026)
MCP Bridge: A Lightweight, LLM-Agnostic RESTful Proxy for Model Context Protocol Servers
by: Ahmadi, Arash, et al.
Published: (2025)
by: Ahmadi, Arash, et al.
Published: (2025)
MCP-38: A Comprehensive Threat Taxonomy for Model Context Protocol Systems (v1.0)
by: Shen, Yi Ting, et al.
Published: (2026)
by: Shen, Yi Ting, et al.
Published: (2026)
Give Them an Inch and They Will Take a Mile:Understanding and Measuring Caller Identity Confusion in MCP-Based AI Systems
by: Huang, Yuhang, et al.
Published: (2026)
by: Huang, Yuhang, et al.
Published: (2026)
ETDI: Mitigating Tool Squatting and Rug Pull Attacks in Model Context Protocol (MCP) by using OAuth-Enhanced Tool Definitions and Policy-Based Access Control
by: Bhatt, Manish, et al.
Published: (2025)
by: Bhatt, Manish, et al.
Published: (2025)
Security Threat Modeling for Emerging AI-Agent Protocols: A Comparative Analysis of MCP, A2A, Agora, and ANP
by: Anbiaee, Zeynab, et al.
Published: (2026)
by: Anbiaee, Zeynab, et al.
Published: (2026)
Agentic-AI Healthcare: Multilingual, Privacy-First Framework with MCP Agents
by: Shehab, Mohammed A.
Published: (2025)
by: Shehab, Mohammed A.
Published: (2025)
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models
by: Belkhiter, Yannis, et al.
Published: (2026)
by: Belkhiter, Yannis, et al.
Published: (2026)
MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits
by: Radosevich, Brandon, et al.
Published: (2025)
by: Radosevich, Brandon, et al.
Published: (2025)
On The Dangers of Poisoned LLMs In Security Automation
by: Karlsen, Patrick, et al.
Published: (2025)
by: Karlsen, Patrick, et al.
Published: (2025)
IntentMiner: Intent Inversion Attack via Tool Call Analysis in the Model Context Protocol
by: Yao, Yunhao, et al.
Published: (2025)
by: Yao, Yunhao, et al.
Published: (2025)
MCP Pitfall Lab: Exposing Developer Pitfalls in MCP Tool Server Security under Multi-Vector Attacks
by: Hao, Run, et al.
Published: (2026)
by: Hao, Run, et al.
Published: (2026)
MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools
by: Tan, Zhuoran, et al.
Published: (2026)
by: Tan, Zhuoran, et al.
Published: (2026)
Secure Multi-Modal Data Fusion in Federated Digital Health Systems via MCP
by: Aueawatthanaphisut, Aueaphum
Published: (2025)
by: Aueawatthanaphisut, Aueaphum
Published: (2025)
The Stronger the Diffusion Model, the Easier the Backdoor: Data Poisoning to Induce Copyright Breaches Without Adjusting Finetuning Pipeline
by: Wang, Haonan, et al.
Published: (2024)
by: Wang, Haonan, et al.
Published: (2024)
One Shot Dominance: Knowledge Poisoning Attack on Retrieval-Augmented Generation Systems
by: Chang, Zhiyuan, et al.
Published: (2025)
by: Chang, Zhiyuan, et al.
Published: (2025)
Toward Polymorphic Backdoor against Semantic Communication via Intensity-Based Poisoning
by: Yang, Xiao, et al.
Published: (2026)
by: Yang, Xiao, et al.
Published: (2026)
AegisMCP: Online Graph Intrusion Detection for Tool-Augmented LLMs on Edge Devices
by: Zhan, Zhonghao, et al.
Published: (2025)
by: Zhan, Zhonghao, et al.
Published: (2025)
Similar Items
-
MCP-in-SoS: Risk assessment framework for open-source MCP servers
by: Kumar, Pratyay, et al.
Published: (2026) -
When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents
by: Liu, Shi, et al.
Published: (2026) -
MCPGuard : Automatically Detecting Vulnerabilities in MCP Servers
by: Wang, Bin, et al.
Published: (2025) -
MCP Guardian: A Security-First Layer for Safeguarding MCP-Based AI System
by: Kumar, Sonu, et al.
Published: (2025) -
We Urgently Need Privilege Management in MCP: A Measurement of API Usage in MCP Ecosystems
by: Li, Zhihao, et al.
Published: (2025)