Breaking the Protocol: Security Analysis of the Model Context Protocol Specification and Prompt Injection Vulnerabilities in Tool-Integrated LLM Agents
Fuente:
arXiv
Guardado en:
| Autores principales: | Maloyan, Narek, Namiot, Dmitry |
|---|---|
| Formato: | Preprint |
| Publicado: |
2026
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
Ejemplares similares
Prompt Injection Attacks on Agentic Coding Assistants: A Systematic Analysis of Vulnerabilities in Skills, Tools, and Protocol Ecosystems
por: Maloyan, Narek, et al.
Publicado: (2026)
por: Maloyan, Narek, et al.
Publicado: (2026)
Sleeper Channels and Provenance Gates: Persistent Prompt Injection in Always-on Autonomous AI Agents
por: Maloyan, Narek, et al.
Publicado: (2026)
por: Maloyan, Narek, et al.
Publicado: (2026)
Adversarial Attacks on LLM-as-a-Judge Systems: Insights from Prompt Injections
por: Maloyan, Narek, et al.
Publicado: (2025)
por: Maloyan, Narek, et al.
Publicado: (2025)
Investigating the Vulnerability of LLM-as-a-Judge Architectures to Prompt-Injection Attacks
por: Maloyan, Narek, et al.
Publicado: (2025)
por: Maloyan, Narek, et al.
Publicado: (2025)
From Prompt Injections to Protocol Exploits: Threats in LLM-Powered AI Agents Workflows
por: Ferrag, Mohamed Amine, et al.
Publicado: (2025)
por: Ferrag, Mohamed Amine, et al.
Publicado: (2025)
OpenPort Protocol: A Security Governance Specification for AI Agent Tool Access
por: Zhu, Genliang, et al.
Publicado: (2026)
por: Zhu, Genliang, et al.
Publicado: (2026)
MCP Security Bench (MSB): Benchmarking Attacks Against Model Context Protocol in LLM Agents
por: Zhang, Dongsen, et al.
Publicado: (2025)
por: Zhang, Dongsen, et al.
Publicado: (2025)
Automatic Red Teaming LLM-based Agents with Model Context Protocol Tools
por: He, Ping, et al.
Publicado: (2025)
por: He, Ping, et al.
Publicado: (2025)
Whispers of Wealth: Red-Teaming Google's Agent Payments Protocol via Prompt Injection
por: Debi, Tanusree, et al.
Publicado: (2026)
por: Debi, Tanusree, et al.
Publicado: (2026)
ASPI: Seeking Ambiguity Clarification Amplifies Prompt Injection Vulnerability in LLM Agents
por: Sehwag, Udari Madhushani, et al.
Publicado: (2026)
por: Sehwag, Udari Madhushani, et al.
Publicado: (2026)
ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection
por: Zhao, Wei, et al.
Publicado: (2026)
por: Zhao, Wei, et al.
Publicado: (2026)
Semantic Attacks on Tool-Augmented LLMs: Securing the Model Context Protocol Against Descriptor-Level Manipulation
por: Jamshidi, Saeid, et al.
Publicado: (2025)
por: Jamshidi, Saeid, et al.
Publicado: (2025)
Systematization of Knowledge: Security and Safety in the Model Context Protocol Ecosystem
por: Gaire, Shiva, et al.
Publicado: (2025)
por: Gaire, Shiva, et al.
Publicado: (2025)
A First Look at the Security Issues in the Model Context Protocol Ecosystem
por: Li, Xiaofan, et al.
Publicado: (2025)
por: Li, Xiaofan, et al.
Publicado: (2025)
MCP-DPT: A Defense-Placement Taxonomy and Coverage Analysis for Model Context Protocol Security
por: Rostamzadeh, Mehrdad, et al.
Publicado: (2026)
por: Rostamzadeh, Mehrdad, et al.
Publicado: (2026)
Model Context Protocol Threat Modeling and Analyzing Vulnerabilities to Prompt Injection with Tool Poisoning
por: Huang, Charoes, et al.
Publicado: (2026)
por: Huang, Charoes, et al.
Publicado: (2026)
Enterprise-Grade Security for the Model Context Protocol (MCP): Frameworks and Mitigation Strategies
por: Narajala, Vineeth Sai, et al.
Publicado: (2025)
por: Narajala, Vineeth Sai, et al.
Publicado: (2025)
Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions
por: Hou, Xinyi, et al.
Publicado: (2025)
por: Hou, Xinyi, et al.
Publicado: (2025)
Tailored Prompts, Targeted Protection: Vulnerability-Specific LLM Analysis for Smart Contracts
por: Zhang, Xing, et al.
Publicado: (2026)
por: Zhang, Xing, et al.
Publicado: (2026)
Securing AI Agents Against Prompt Injection Attacks
por: Ramakrishnan, Badrinath, et al.
Publicado: (2025)
por: Ramakrishnan, Badrinath, et al.
Publicado: (2025)
MCPSecBench: A Systematic Security Benchmark and Playground for Testing Model Context Protocols
por: Yang, Yixuan, et al.
Publicado: (2025)
por: Yang, Yixuan, et al.
Publicado: (2025)
To Protect the LLM Agent Against the Prompt Injection Attack with Polymorphic Prompt
por: Wang, Zhilong, et al.
Publicado: (2025)
por: Wang, Zhilong, et al.
Publicado: (2025)
MCPXKIT: The Unified Toolkit for Analyzing Model Context Protocol Security
por: Guo, Yongjian, et al.
Publicado: (2025)
por: Guo, Yongjian, et al.
Publicado: (2025)
WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks
por: Evtimov, Ivan, et al.
Publicado: (2025)
por: Evtimov, Ivan, et al.
Publicado: (2025)
Agentic JWT: A Secure Delegation Protocol for Autonomous AI Agents
por: Goswami, Abhishek
Publicado: (2025)
por: Goswami, Abhishek
Publicado: (2025)
The System Prompt Is the Attack Surface: How LLM Agent Configuration Shapes Security and Creates Exploitable Vulnerabilities
por: Litvak, Ron
Publicado: (2026)
por: Litvak, Ron
Publicado: (2026)
Invisible Threats from Model Context Protocol: Generating Stealthy Injection Payload via Tree-based Adaptive Search
por: Shen, Yulin, et al.
Publicado: (2026)
por: Shen, Yulin, et al.
Publicado: (2026)
What Breaks Embodied AI Security:LLM Vulnerabilities, CPS Flaws,or Something Else?
por: Ma, Boyang, et al.
Publicado: (2026)
por: Ma, Boyang, et al.
Publicado: (2026)
MCP Bridge: A Lightweight, LLM-Agnostic RESTful Proxy for Model Context Protocol Servers
por: Ahmadi, Arash, et al.
Publicado: (2025)
por: Ahmadi, Arash, et al.
Publicado: (2025)
Zero-Knowledge Audit for Internet of Agents: Privacy-Preserving Communication Verification with Model Context Protocol
por: Jing, Guanlin, et al.
Publicado: (2025)
por: Jing, Guanlin, et al.
Publicado: (2025)
Security Threat Modeling for Emerging AI-Agent Protocols: A Comparative Analysis of MCP, A2A, Agora, and ANP
por: Anbiaee, Zeynab, et al.
Publicado: (2026)
por: Anbiaee, Zeynab, et al.
Publicado: (2026)
MCP-Guard: A Multi-Stage Defense-in-Depth Framework for Securing Model Context Protocol in Agentic AI
por: Xing, Wenpeng, et al.
Publicado: (2025)
por: Xing, Wenpeng, et al.
Publicado: (2025)
RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage
por: Zhong, Peter Yong, et al.
Publicado: (2025)
por: Zhong, Peter Yong, et al.
Publicado: (2025)
SAMEP: A Secure Protocol for Persistent Context Sharing Across AI Agents
por: Masoor, Hari
Publicado: (2025)
por: Masoor, Hari
Publicado: (2025)
Meta SecAlign: A Secure Foundation LLM Against Prompt Injection Attacks
por: Chen, Sizhe, et al.
Publicado: (2025)
por: Chen, Sizhe, et al.
Publicado: (2025)
Signed-Prompt: A New Approach to Prevent Prompt Injection Attacks Against LLM-Integrated Applications
por: Suo, Xuchen
Publicado: (2024)
por: Suo, Xuchen
Publicado: (2024)
How Vulnerable Are AI Agents to Indirect Prompt Injections? Insights from a Large-Scale Public Competition
por: Dziemian, Mateusz, et al.
Publicado: (2026)
por: Dziemian, Mateusz, et al.
Publicado: (2026)
DRIFT: Dynamic Rule-Based Defense with Injection Isolation for Securing LLM Agents
por: Li, Hao, et al.
Publicado: (2025)
por: Li, Hao, et al.
Publicado: (2025)
MCPThreatHive: Automated Threat Intelligence for Model Context Protocol Ecosystems
por: Shen, Yi Ting, et al.
Publicado: (2026)
por: Shen, Yi Ting, et al.
Publicado: (2026)
F2A: An Innovative Approach for Prompt Injection by Utilizing Feign Security Detection Agents
por: Ren, Yupeng
Publicado: (2024)
por: Ren, Yupeng
Publicado: (2024)
Ejemplares similares
-
Prompt Injection Attacks on Agentic Coding Assistants: A Systematic Analysis of Vulnerabilities in Skills, Tools, and Protocol Ecosystems
por: Maloyan, Narek, et al.
Publicado: (2026) -
Sleeper Channels and Provenance Gates: Persistent Prompt Injection in Always-on Autonomous AI Agents
por: Maloyan, Narek, et al.
Publicado: (2026) -
Adversarial Attacks on LLM-as-a-Judge Systems: Insights from Prompt Injections
por: Maloyan, Narek, et al.
Publicado: (2025) -
Investigating the Vulnerability of LLM-as-a-Judge Architectures to Prompt-Injection Attacks
por: Maloyan, Narek, et al.
Publicado: (2025) -
From Prompt Injections to Protocol Exploits: Threats in LLM-Powered AI Agents Workflows
por: Ferrag, Mohamed Amine, et al.
Publicado: (2025)