Breaking the Protocol: Security Analysis of the Model Context Protocol Specification and Prompt Injection Vulnerabilities in Tool-Integrated LLM Agents
Fuente:
arXiv
Salvato in:
| Autori principali: | Maloyan, Narek, Namiot, Dmitry |
|---|---|
| Natura: | Preprint |
| Pubblicazione: |
2026
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
Documenti analoghi
Prompt Injection Attacks on Agentic Coding Assistants: A Systematic Analysis of Vulnerabilities in Skills, Tools, and Protocol Ecosystems
di: Maloyan, Narek, et al.
Pubblicazione: (2026)
di: Maloyan, Narek, et al.
Pubblicazione: (2026)
Sleeper Channels and Provenance Gates: Persistent Prompt Injection in Always-on Autonomous AI Agents
di: Maloyan, Narek, et al.
Pubblicazione: (2026)
di: Maloyan, Narek, et al.
Pubblicazione: (2026)
Adversarial Attacks on LLM-as-a-Judge Systems: Insights from Prompt Injections
di: Maloyan, Narek, et al.
Pubblicazione: (2025)
di: Maloyan, Narek, et al.
Pubblicazione: (2025)
Investigating the Vulnerability of LLM-as-a-Judge Architectures to Prompt-Injection Attacks
di: Maloyan, Narek, et al.
Pubblicazione: (2025)
di: Maloyan, Narek, et al.
Pubblicazione: (2025)
From Prompt Injections to Protocol Exploits: Threats in LLM-Powered AI Agents Workflows
di: Ferrag, Mohamed Amine, et al.
Pubblicazione: (2025)
di: Ferrag, Mohamed Amine, et al.
Pubblicazione: (2025)
OpenPort Protocol: A Security Governance Specification for AI Agent Tool Access
di: Zhu, Genliang, et al.
Pubblicazione: (2026)
di: Zhu, Genliang, et al.
Pubblicazione: (2026)
MCP Security Bench (MSB): Benchmarking Attacks Against Model Context Protocol in LLM Agents
di: Zhang, Dongsen, et al.
Pubblicazione: (2025)
di: Zhang, Dongsen, et al.
Pubblicazione: (2025)
Automatic Red Teaming LLM-based Agents with Model Context Protocol Tools
di: He, Ping, et al.
Pubblicazione: (2025)
di: He, Ping, et al.
Pubblicazione: (2025)
Whispers of Wealth: Red-Teaming Google's Agent Payments Protocol via Prompt Injection
di: Debi, Tanusree, et al.
Pubblicazione: (2026)
di: Debi, Tanusree, et al.
Pubblicazione: (2026)
ASPI: Seeking Ambiguity Clarification Amplifies Prompt Injection Vulnerability in LLM Agents
di: Sehwag, Udari Madhushani, et al.
Pubblicazione: (2026)
di: Sehwag, Udari Madhushani, et al.
Pubblicazione: (2026)
ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection
di: Zhao, Wei, et al.
Pubblicazione: (2026)
di: Zhao, Wei, et al.
Pubblicazione: (2026)
Semantic Attacks on Tool-Augmented LLMs: Securing the Model Context Protocol Against Descriptor-Level Manipulation
di: Jamshidi, Saeid, et al.
Pubblicazione: (2025)
di: Jamshidi, Saeid, et al.
Pubblicazione: (2025)
Systematization of Knowledge: Security and Safety in the Model Context Protocol Ecosystem
di: Gaire, Shiva, et al.
Pubblicazione: (2025)
di: Gaire, Shiva, et al.
Pubblicazione: (2025)
A First Look at the Security Issues in the Model Context Protocol Ecosystem
di: Li, Xiaofan, et al.
Pubblicazione: (2025)
di: Li, Xiaofan, et al.
Pubblicazione: (2025)
MCP-DPT: A Defense-Placement Taxonomy and Coverage Analysis for Model Context Protocol Security
di: Rostamzadeh, Mehrdad, et al.
Pubblicazione: (2026)
di: Rostamzadeh, Mehrdad, et al.
Pubblicazione: (2026)
Model Context Protocol Threat Modeling and Analyzing Vulnerabilities to Prompt Injection with Tool Poisoning
di: Huang, Charoes, et al.
Pubblicazione: (2026)
di: Huang, Charoes, et al.
Pubblicazione: (2026)
Enterprise-Grade Security for the Model Context Protocol (MCP): Frameworks and Mitigation Strategies
di: Narajala, Vineeth Sai, et al.
Pubblicazione: (2025)
di: Narajala, Vineeth Sai, et al.
Pubblicazione: (2025)
Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions
di: Hou, Xinyi, et al.
Pubblicazione: (2025)
di: Hou, Xinyi, et al.
Pubblicazione: (2025)
Tailored Prompts, Targeted Protection: Vulnerability-Specific LLM Analysis for Smart Contracts
di: Zhang, Xing, et al.
Pubblicazione: (2026)
di: Zhang, Xing, et al.
Pubblicazione: (2026)
Securing AI Agents Against Prompt Injection Attacks
di: Ramakrishnan, Badrinath, et al.
Pubblicazione: (2025)
di: Ramakrishnan, Badrinath, et al.
Pubblicazione: (2025)
MCPSecBench: A Systematic Security Benchmark and Playground for Testing Model Context Protocols
di: Yang, Yixuan, et al.
Pubblicazione: (2025)
di: Yang, Yixuan, et al.
Pubblicazione: (2025)
To Protect the LLM Agent Against the Prompt Injection Attack with Polymorphic Prompt
di: Wang, Zhilong, et al.
Pubblicazione: (2025)
di: Wang, Zhilong, et al.
Pubblicazione: (2025)
MCPXKIT: The Unified Toolkit for Analyzing Model Context Protocol Security
di: Guo, Yongjian, et al.
Pubblicazione: (2025)
di: Guo, Yongjian, et al.
Pubblicazione: (2025)
WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks
di: Evtimov, Ivan, et al.
Pubblicazione: (2025)
di: Evtimov, Ivan, et al.
Pubblicazione: (2025)
Agentic JWT: A Secure Delegation Protocol for Autonomous AI Agents
di: Goswami, Abhishek
Pubblicazione: (2025)
di: Goswami, Abhishek
Pubblicazione: (2025)
The System Prompt Is the Attack Surface: How LLM Agent Configuration Shapes Security and Creates Exploitable Vulnerabilities
di: Litvak, Ron
Pubblicazione: (2026)
di: Litvak, Ron
Pubblicazione: (2026)
Invisible Threats from Model Context Protocol: Generating Stealthy Injection Payload via Tree-based Adaptive Search
di: Shen, Yulin, et al.
Pubblicazione: (2026)
di: Shen, Yulin, et al.
Pubblicazione: (2026)
What Breaks Embodied AI Security:LLM Vulnerabilities, CPS Flaws,or Something Else?
di: Ma, Boyang, et al.
Pubblicazione: (2026)
di: Ma, Boyang, et al.
Pubblicazione: (2026)
MCP Bridge: A Lightweight, LLM-Agnostic RESTful Proxy for Model Context Protocol Servers
di: Ahmadi, Arash, et al.
Pubblicazione: (2025)
di: Ahmadi, Arash, et al.
Pubblicazione: (2025)
Zero-Knowledge Audit for Internet of Agents: Privacy-Preserving Communication Verification with Model Context Protocol
di: Jing, Guanlin, et al.
Pubblicazione: (2025)
di: Jing, Guanlin, et al.
Pubblicazione: (2025)
Security Threat Modeling for Emerging AI-Agent Protocols: A Comparative Analysis of MCP, A2A, Agora, and ANP
di: Anbiaee, Zeynab, et al.
Pubblicazione: (2026)
di: Anbiaee, Zeynab, et al.
Pubblicazione: (2026)
MCP-Guard: A Multi-Stage Defense-in-Depth Framework for Securing Model Context Protocol in Agentic AI
di: Xing, Wenpeng, et al.
Pubblicazione: (2025)
di: Xing, Wenpeng, et al.
Pubblicazione: (2025)
RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage
di: Zhong, Peter Yong, et al.
Pubblicazione: (2025)
di: Zhong, Peter Yong, et al.
Pubblicazione: (2025)
SAMEP: A Secure Protocol for Persistent Context Sharing Across AI Agents
di: Masoor, Hari
Pubblicazione: (2025)
di: Masoor, Hari
Pubblicazione: (2025)
Meta SecAlign: A Secure Foundation LLM Against Prompt Injection Attacks
di: Chen, Sizhe, et al.
Pubblicazione: (2025)
di: Chen, Sizhe, et al.
Pubblicazione: (2025)
Signed-Prompt: A New Approach to Prevent Prompt Injection Attacks Against LLM-Integrated Applications
di: Suo, Xuchen
Pubblicazione: (2024)
di: Suo, Xuchen
Pubblicazione: (2024)
How Vulnerable Are AI Agents to Indirect Prompt Injections? Insights from a Large-Scale Public Competition
di: Dziemian, Mateusz, et al.
Pubblicazione: (2026)
di: Dziemian, Mateusz, et al.
Pubblicazione: (2026)
DRIFT: Dynamic Rule-Based Defense with Injection Isolation for Securing LLM Agents
di: Li, Hao, et al.
Pubblicazione: (2025)
di: Li, Hao, et al.
Pubblicazione: (2025)
MCPThreatHive: Automated Threat Intelligence for Model Context Protocol Ecosystems
di: Shen, Yi Ting, et al.
Pubblicazione: (2026)
di: Shen, Yi Ting, et al.
Pubblicazione: (2026)
F2A: An Innovative Approach for Prompt Injection by Utilizing Feign Security Detection Agents
di: Ren, Yupeng
Pubblicazione: (2024)
di: Ren, Yupeng
Pubblicazione: (2024)
Documenti analoghi
-
Prompt Injection Attacks on Agentic Coding Assistants: A Systematic Analysis of Vulnerabilities in Skills, Tools, and Protocol Ecosystems
di: Maloyan, Narek, et al.
Pubblicazione: (2026) -
Sleeper Channels and Provenance Gates: Persistent Prompt Injection in Always-on Autonomous AI Agents
di: Maloyan, Narek, et al.
Pubblicazione: (2026) -
Adversarial Attacks on LLM-as-a-Judge Systems: Insights from Prompt Injections
di: Maloyan, Narek, et al.
Pubblicazione: (2025) -
Investigating the Vulnerability of LLM-as-a-Judge Architectures to Prompt-Injection Attacks
di: Maloyan, Narek, et al.
Pubblicazione: (2025) -
From Prompt Injections to Protocol Exploits: Threats in LLM-Powered AI Agents Workflows
di: Ferrag, Mohamed Amine, et al.
Pubblicazione: (2025)