MCP-38: A Comprehensive Threat Taxonomy for Model Context Protocol Systems (v1.0)

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Shen, Yi Ting, Toyoda, Kentaroh, Leung, Alex
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908899630645248
author Shen, Yi Ting
Toyoda, Kentaroh
Leung, Alex
author_facet Shen, Yi Ting
Toyoda, Kentaroh
Leung, Alex
contents The Model Context Protocol (MCP) introduces a structurally distinct attack surface that existing threat frameworks, designed for traditional software systems or generic LLM deployments, do not adequately cover. This paper presents MCP-38, a protocol-specific threat taxonomy consisting of 38 threat categories (MCP-01 through MCP-38). The taxonomy was derived through a systematic four-phase methodology: protocol decomposition, multi-framework cross-mapping, real-world incident synthesis, and remediation-surface categorization. Each category is mapped to STRIDE, OWASP Top 10 for LLM Applications (2025, LLM01--LLM10), and the OWASP Top 10 for Agentic Applications (2026, ASI01--ASI10). MCP-38 addresses critical threats arising from MCP's semantic attack surface (tool description poisoning, indirect prompt injection, parasitic tool chaining, and dynamic trust violations), none of which are adequately captured by prior work. MCP-38 provides the definitional and empirical foundation for automated threat intelligence platforms.
format Preprint
id arxiv_https___arxiv_org_abs_2603_18063
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle MCP-38: A Comprehensive Threat Taxonomy for Model Context Protocol Systems (v1.0)
Shen, Yi Ting
Toyoda, Kentaroh
Leung, Alex
Cryptography and Security
Artificial Intelligence
The Model Context Protocol (MCP) introduces a structurally distinct attack surface that existing threat frameworks, designed for traditional software systems or generic LLM deployments, do not adequately cover. This paper presents MCP-38, a protocol-specific threat taxonomy consisting of 38 threat categories (MCP-01 through MCP-38). The taxonomy was derived through a systematic four-phase methodology: protocol decomposition, multi-framework cross-mapping, real-world incident synthesis, and remediation-surface categorization. Each category is mapped to STRIDE, OWASP Top 10 for LLM Applications (2025, LLM01--LLM10), and the OWASP Top 10 for Agentic Applications (2026, ASI01--ASI10). MCP-38 addresses critical threats arising from MCP's semantic attack surface (tool description poisoning, indirect prompt injection, parasitic tool chaining, and dynamic trust violations), none of which are adequately captured by prior work. MCP-38 provides the definitional and empirical foundation for automated threat intelligence platforms.
title MCP-38: A Comprehensive Threat Taxonomy for Model Context Protocol Systems (v1.0)
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2603.18063