Breaking the Protocol: Security Analysis of the Model Context Protocol Specification and Prompt Injection Vulnerabilities in Tool-Integrated LLM Agents
Fuente:
arXiv
Enregistré dans:
| Auteurs principaux: | Maloyan, Narek, Namiot, Dmitry |
|---|---|
| Format: | Preprint |
| Publié: |
2026
|
| Sujets: | |
| Accès en ligne: | |
| Tags: |
Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
|
Documents similaires
Prompt Injection Attacks on Agentic Coding Assistants: A Systematic Analysis of Vulnerabilities in Skills, Tools, and Protocol Ecosystems
par: Maloyan, Narek, et autres
Publié: (2026)
par: Maloyan, Narek, et autres
Publié: (2026)
Sleeper Channels and Provenance Gates: Persistent Prompt Injection in Always-on Autonomous AI Agents
par: Maloyan, Narek, et autres
Publié: (2026)
par: Maloyan, Narek, et autres
Publié: (2026)
Adversarial Attacks on LLM-as-a-Judge Systems: Insights from Prompt Injections
par: Maloyan, Narek, et autres
Publié: (2025)
par: Maloyan, Narek, et autres
Publié: (2025)
Investigating the Vulnerability of LLM-as-a-Judge Architectures to Prompt-Injection Attacks
par: Maloyan, Narek, et autres
Publié: (2025)
par: Maloyan, Narek, et autres
Publié: (2025)
From Prompt Injections to Protocol Exploits: Threats in LLM-Powered AI Agents Workflows
par: Ferrag, Mohamed Amine, et autres
Publié: (2025)
par: Ferrag, Mohamed Amine, et autres
Publié: (2025)
OpenPort Protocol: A Security Governance Specification for AI Agent Tool Access
par: Zhu, Genliang, et autres
Publié: (2026)
par: Zhu, Genliang, et autres
Publié: (2026)
MCP Security Bench (MSB): Benchmarking Attacks Against Model Context Protocol in LLM Agents
par: Zhang, Dongsen, et autres
Publié: (2025)
par: Zhang, Dongsen, et autres
Publié: (2025)
Automatic Red Teaming LLM-based Agents with Model Context Protocol Tools
par: He, Ping, et autres
Publié: (2025)
par: He, Ping, et autres
Publié: (2025)
Whispers of Wealth: Red-Teaming Google's Agent Payments Protocol via Prompt Injection
par: Debi, Tanusree, et autres
Publié: (2026)
par: Debi, Tanusree, et autres
Publié: (2026)
ASPI: Seeking Ambiguity Clarification Amplifies Prompt Injection Vulnerability in LLM Agents
par: Sehwag, Udari Madhushani, et autres
Publié: (2026)
par: Sehwag, Udari Madhushani, et autres
Publié: (2026)
ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection
par: Zhao, Wei, et autres
Publié: (2026)
par: Zhao, Wei, et autres
Publié: (2026)
Semantic Attacks on Tool-Augmented LLMs: Securing the Model Context Protocol Against Descriptor-Level Manipulation
par: Jamshidi, Saeid, et autres
Publié: (2025)
par: Jamshidi, Saeid, et autres
Publié: (2025)
Systematization of Knowledge: Security and Safety in the Model Context Protocol Ecosystem
par: Gaire, Shiva, et autres
Publié: (2025)
par: Gaire, Shiva, et autres
Publié: (2025)
A First Look at the Security Issues in the Model Context Protocol Ecosystem
par: Li, Xiaofan, et autres
Publié: (2025)
par: Li, Xiaofan, et autres
Publié: (2025)
MCP-DPT: A Defense-Placement Taxonomy and Coverage Analysis for Model Context Protocol Security
par: Rostamzadeh, Mehrdad, et autres
Publié: (2026)
par: Rostamzadeh, Mehrdad, et autres
Publié: (2026)
Model Context Protocol Threat Modeling and Analyzing Vulnerabilities to Prompt Injection with Tool Poisoning
par: Huang, Charoes, et autres
Publié: (2026)
par: Huang, Charoes, et autres
Publié: (2026)
Enterprise-Grade Security for the Model Context Protocol (MCP): Frameworks and Mitigation Strategies
par: Narajala, Vineeth Sai, et autres
Publié: (2025)
par: Narajala, Vineeth Sai, et autres
Publié: (2025)
Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions
par: Hou, Xinyi, et autres
Publié: (2025)
par: Hou, Xinyi, et autres
Publié: (2025)
Tailored Prompts, Targeted Protection: Vulnerability-Specific LLM Analysis for Smart Contracts
par: Zhang, Xing, et autres
Publié: (2026)
par: Zhang, Xing, et autres
Publié: (2026)
Securing AI Agents Against Prompt Injection Attacks
par: Ramakrishnan, Badrinath, et autres
Publié: (2025)
par: Ramakrishnan, Badrinath, et autres
Publié: (2025)
MCPSecBench: A Systematic Security Benchmark and Playground for Testing Model Context Protocols
par: Yang, Yixuan, et autres
Publié: (2025)
par: Yang, Yixuan, et autres
Publié: (2025)
To Protect the LLM Agent Against the Prompt Injection Attack with Polymorphic Prompt
par: Wang, Zhilong, et autres
Publié: (2025)
par: Wang, Zhilong, et autres
Publié: (2025)
MCPXKIT: The Unified Toolkit for Analyzing Model Context Protocol Security
par: Guo, Yongjian, et autres
Publié: (2025)
par: Guo, Yongjian, et autres
Publié: (2025)
WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks
par: Evtimov, Ivan, et autres
Publié: (2025)
par: Evtimov, Ivan, et autres
Publié: (2025)
Agentic JWT: A Secure Delegation Protocol for Autonomous AI Agents
par: Goswami, Abhishek
Publié: (2025)
par: Goswami, Abhishek
Publié: (2025)
The System Prompt Is the Attack Surface: How LLM Agent Configuration Shapes Security and Creates Exploitable Vulnerabilities
par: Litvak, Ron
Publié: (2026)
par: Litvak, Ron
Publié: (2026)
Invisible Threats from Model Context Protocol: Generating Stealthy Injection Payload via Tree-based Adaptive Search
par: Shen, Yulin, et autres
Publié: (2026)
par: Shen, Yulin, et autres
Publié: (2026)
What Breaks Embodied AI Security:LLM Vulnerabilities, CPS Flaws,or Something Else?
par: Ma, Boyang, et autres
Publié: (2026)
par: Ma, Boyang, et autres
Publié: (2026)
MCP Bridge: A Lightweight, LLM-Agnostic RESTful Proxy for Model Context Protocol Servers
par: Ahmadi, Arash, et autres
Publié: (2025)
par: Ahmadi, Arash, et autres
Publié: (2025)
Zero-Knowledge Audit for Internet of Agents: Privacy-Preserving Communication Verification with Model Context Protocol
par: Jing, Guanlin, et autres
Publié: (2025)
par: Jing, Guanlin, et autres
Publié: (2025)
Security Threat Modeling for Emerging AI-Agent Protocols: A Comparative Analysis of MCP, A2A, Agora, and ANP
par: Anbiaee, Zeynab, et autres
Publié: (2026)
par: Anbiaee, Zeynab, et autres
Publié: (2026)
MCP-Guard: A Multi-Stage Defense-in-Depth Framework for Securing Model Context Protocol in Agentic AI
par: Xing, Wenpeng, et autres
Publié: (2025)
par: Xing, Wenpeng, et autres
Publié: (2025)
RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage
par: Zhong, Peter Yong, et autres
Publié: (2025)
par: Zhong, Peter Yong, et autres
Publié: (2025)
SAMEP: A Secure Protocol for Persistent Context Sharing Across AI Agents
par: Masoor, Hari
Publié: (2025)
par: Masoor, Hari
Publié: (2025)
Meta SecAlign: A Secure Foundation LLM Against Prompt Injection Attacks
par: Chen, Sizhe, et autres
Publié: (2025)
par: Chen, Sizhe, et autres
Publié: (2025)
Signed-Prompt: A New Approach to Prevent Prompt Injection Attacks Against LLM-Integrated Applications
par: Suo, Xuchen
Publié: (2024)
par: Suo, Xuchen
Publié: (2024)
How Vulnerable Are AI Agents to Indirect Prompt Injections? Insights from a Large-Scale Public Competition
par: Dziemian, Mateusz, et autres
Publié: (2026)
par: Dziemian, Mateusz, et autres
Publié: (2026)
DRIFT: Dynamic Rule-Based Defense with Injection Isolation for Securing LLM Agents
par: Li, Hao, et autres
Publié: (2025)
par: Li, Hao, et autres
Publié: (2025)
MCPThreatHive: Automated Threat Intelligence for Model Context Protocol Ecosystems
par: Shen, Yi Ting, et autres
Publié: (2026)
par: Shen, Yi Ting, et autres
Publié: (2026)
F2A: An Innovative Approach for Prompt Injection by Utilizing Feign Security Detection Agents
par: Ren, Yupeng
Publié: (2024)
par: Ren, Yupeng
Publié: (2024)
Documents similaires
-
Prompt Injection Attacks on Agentic Coding Assistants: A Systematic Analysis of Vulnerabilities in Skills, Tools, and Protocol Ecosystems
par: Maloyan, Narek, et autres
Publié: (2026) -
Sleeper Channels and Provenance Gates: Persistent Prompt Injection in Always-on Autonomous AI Agents
par: Maloyan, Narek, et autres
Publié: (2026) -
Adversarial Attacks on LLM-as-a-Judge Systems: Insights from Prompt Injections
par: Maloyan, Narek, et autres
Publié: (2025) -
Investigating the Vulnerability of LLM-as-a-Judge Architectures to Prompt-Injection Attacks
par: Maloyan, Narek, et autres
Publié: (2025) -
From Prompt Injections to Protocol Exploits: Threats in LLM-Powered AI Agents Workflows
par: Ferrag, Mohamed Amine, et autres
Publié: (2025)