MCPThreatHive: Automated Threat Intelligence for Model Context Protocol Ecosystems

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Shen, Yi Ting, Toyoda, Kentaroh, Leung, Alex
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910131521847296
author Shen, Yi Ting
Toyoda, Kentaroh
Leung, Alex
author_facet Shen, Yi Ting
Toyoda, Kentaroh
Leung, Alex
contents The rapid proliferation of Model Context Protocol (MCP)-based agentic systems has introduced a new category of security threats that existing frameworks are inadequately equipped to address. We present MCPThreatHive, an open-source platform that automates the end-to-end lifecycle of MCP threat intelligence: from continuous, multi-source data collection through AI-driven threat extraction and classification, to structured knowledge graph storage and interactive visualization. The platform operationalizes the MCP-38 threat taxonomy, a curated set of 38 MCP-specific threat patterns mapped to STRIDE, OWASP Top 10 for LLM Applications, and OWASP Top 10 for Agentic Applications. A composite risk scoring model provides quantitative prioritization. Through a comparative analysis of representative existing MCP security tools, we identify three critical coverage gaps that MCPThreatHive addresses: incomplete compositional attack modeling, absence of continuous threat intelligence, and lack of unified multi-framework classification.
format Preprint
id arxiv_https___arxiv_org_abs_2604_13849
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle MCPThreatHive: Automated Threat Intelligence for Model Context Protocol Ecosystems
Shen, Yi Ting
Toyoda, Kentaroh
Leung, Alex
Cryptography and Security
Artificial Intelligence
The rapid proliferation of Model Context Protocol (MCP)-based agentic systems has introduced a new category of security threats that existing frameworks are inadequately equipped to address. We present MCPThreatHive, an open-source platform that automates the end-to-end lifecycle of MCP threat intelligence: from continuous, multi-source data collection through AI-driven threat extraction and classification, to structured knowledge graph storage and interactive visualization. The platform operationalizes the MCP-38 threat taxonomy, a curated set of 38 MCP-specific threat patterns mapped to STRIDE, OWASP Top 10 for LLM Applications, and OWASP Top 10 for Agentic Applications. A composite risk scoring model provides quantitative prioritization. Through a comparative analysis of representative existing MCP security tools, we identify three critical coverage gaps that MCPThreatHive addresses: incomplete compositional attack modeling, absence of continuous threat intelligence, and lack of unified multi-framework classification.
title MCPThreatHive: Automated Threat Intelligence for Model Context Protocol Ecosystems
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2604.13849