MCP Pitfall Lab: Exposing Developer Pitfalls in MCP Tool Server Security under Multi-Vector Attacks
Fuente:
arXiv
Gespeichert in:
| Hauptverfasser: | Hao, Run, Tan, Zhuoran |
|---|---|
| Format: | Preprint |
| Veröffentlicht: |
2026
|
| Schlagworte: | |
| Online-Zugang: | |
| Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Ähnliche Einträge
MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools
von: Tan, Zhuoran, et al.
Veröffentlicht: (2026)
von: Tan, Zhuoran, et al.
Veröffentlicht: (2026)
MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
von: Wang, Zhiqiang, et al.
Veröffentlicht: (2025)
von: Wang, Zhiqiang, et al.
Veröffentlicht: (2025)
Auditing MCP Servers for Over-Privileged Tool Capabilities
von: Huang, Charoes, et al.
Veröffentlicht: (2026)
von: Huang, Charoes, et al.
Veröffentlicht: (2026)
When MCP Servers Attack: Taxonomy, Feasibility, and Mitigation
von: Zhao, Weibo, et al.
Veröffentlicht: (2025)
von: Zhao, Weibo, et al.
Veröffentlicht: (2025)
MCPGuard : Automatically Detecting Vulnerabilities in MCP Servers
von: Wang, Bin, et al.
Veröffentlicht: (2025)
von: Wang, Bin, et al.
Veröffentlicht: (2025)
A First Measurement Study on Authentication Security in Real-World Remote MCP Servers
von: Zhou, Huijun, et al.
Veröffentlicht: (2026)
von: Zhou, Huijun, et al.
Veröffentlicht: (2026)
MCP-ITP: An Automated Framework for Implicit Tool Poisoning in MCP
von: Li, Ruiqi, et al.
Veröffentlicht: (2026)
von: Li, Ruiqi, et al.
Veröffentlicht: (2026)
Beyond the Protocol: Unveiling Attack Vectors in the Model Context Protocol (MCP) Ecosystem
von: Song, Hao, et al.
Veröffentlicht: (2025)
von: Song, Hao, et al.
Veröffentlicht: (2025)
Trivial Trojans: How Minimal MCP Servers Enable Cross-Tool Exfiltration of Sensitive Data
von: Croce, Nicola, et al.
Veröffentlicht: (2025)
von: Croce, Nicola, et al.
Veröffentlicht: (2025)
VIPER-MCP: Detecting and Exploiting Taint-Style Vulnerabilities in Model Context Protocol Servers
von: Sun, Pengyu, et al.
Veröffentlicht: (2026)
von: Sun, Pengyu, et al.
Veröffentlicht: (2026)
MCP Guardian: A Security-First Layer for Safeguarding MCP-Based AI System
von: Kumar, Sonu, et al.
Veröffentlicht: (2025)
von: Kumar, Sonu, et al.
Veröffentlicht: (2025)
Chasing Shadows: Pitfalls in LLM Security Research
von: Evertz, Jonathan, et al.
Veröffentlicht: (2025)
von: Evertz, Jonathan, et al.
Veröffentlicht: (2025)
Analysing the Safety Pitfalls of Steering Vectors
von: Li, Yuxiao, et al.
Veröffentlicht: (2026)
von: Li, Yuxiao, et al.
Veröffentlicht: (2026)
Secure Tool Manifest and Digital Signing Solution for Verifiable MCP and LLM Pipelines
von: Jamshidi, Saeid, et al.
Veröffentlicht: (2026)
von: Jamshidi, Saeid, et al.
Veröffentlicht: (2026)
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers
von: Huang, Yiheng, et al.
Veröffentlicht: (2026)
von: Huang, Yiheng, et al.
Veröffentlicht: (2026)
Securing the Model Context Protocol (MCP): Risks, Controls, and Governance
von: Errico, Herman, et al.
Veröffentlicht: (2025)
von: Errico, Herman, et al.
Veröffentlicht: (2025)
Can LLM Infer Risk Information From MCP Server System Logs?
von: Fu, Jiayi, et al.
Veröffentlicht: (2025)
von: Fu, Jiayi, et al.
Veröffentlicht: (2025)
Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP Ecosystem
von: Zhao, Shuli, et al.
Veröffentlicht: (2025)
von: Zhao, Shuli, et al.
Veröffentlicht: (2025)
No More Hidden Pitfalls? Exposing Smart Contract Bad Practices with LLM-Powered Hybrid Analysis
von: Li, Xiaoqi, et al.
Veröffentlicht: (2025)
von: Li, Xiaoqi, et al.
Veröffentlicht: (2025)
Simplified and Secure MCP Gateways for Enterprise AI Integration
von: Brett, Ivo
Veröffentlicht: (2025)
von: Brett, Ivo
Veröffentlicht: (2025)
MCP-in-SoS: Risk assessment framework for open-source MCP servers
von: Kumar, Pratyay, et al.
Veröffentlicht: (2026)
von: Kumar, Pratyay, et al.
Veröffentlicht: (2026)
MCP Security Bench (MSB): Benchmarking Attacks Against Model Context Protocol in LLM Agents
von: Zhang, Dongsen, et al.
Veröffentlicht: (2025)
von: Zhang, Dongsen, et al.
Veröffentlicht: (2025)
MCP Bridge: A Lightweight, LLM-Agnostic RESTful Proxy for Model Context Protocol Servers
von: Ahmadi, Arash, et al.
Veröffentlicht: (2025)
von: Ahmadi, Arash, et al.
Veröffentlicht: (2025)
AegisMCP: Online Graph Intrusion Detection for Tool-Augmented LLMs on Edge Devices
von: Zhan, Zhonghao, et al.
Veröffentlicht: (2025)
von: Zhan, Zhonghao, et al.
Veröffentlicht: (2025)
Overthinking Loops in Agents: A Structural Risk via MCP Tools
von: Lee, Yohan, et al.
Veröffentlicht: (2026)
von: Lee, Yohan, et al.
Veröffentlicht: (2026)
Don't believe everything you read: Understanding and Measuring MCP Behavior under Misleading Tool Descriptions
von: Li, Zhihao, et al.
Veröffentlicht: (2026)
von: Li, Zhihao, et al.
Veröffentlicht: (2026)
MCP Safety Training: Learning to Refuse Falsely Benign MCP Exploits using Improved Preference Alignment
von: Halloran, John
Veröffentlicht: (2025)
von: Halloran, John
Veröffentlicht: (2025)
From Tool Orchestration to Code Execution: A Study of MCP Design Choices
von: Felendler, Yuval, et al.
Veröffentlicht: (2026)
von: Felendler, Yuval, et al.
Veröffentlicht: (2026)
APILOT: Navigating Large Language Models to Generate Secure Code by Sidestepping Outdated API Pitfalls
von: Bai, Weiheng, et al.
Veröffentlicht: (2024)
von: Bai, Weiheng, et al.
Veröffentlicht: (2024)
Enterprise-Grade Security for the Model Context Protocol (MCP): Frameworks and Mitigation Strategies
von: Narajala, Vineeth Sai, et al.
Veröffentlicht: (2025)
von: Narajala, Vineeth Sai, et al.
Veröffentlicht: (2025)
Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions
von: Hou, Xinyi, et al.
Veröffentlicht: (2025)
von: Hou, Xinyi, et al.
Veröffentlicht: (2025)
The Pitfalls of "Security by Obscurity" And What They Mean for Transparent AI
von: Hall, Peter, et al.
Veröffentlicht: (2025)
von: Hall, Peter, et al.
Veröffentlicht: (2025)
Potentials and Pitfalls of Applying Federated Learning in Hardware Assurance
von: Lee, Gijung, et al.
Veröffentlicht: (2026)
von: Lee, Gijung, et al.
Veröffentlicht: (2026)
SoK: An Essential Guide For Using Malware Sandboxes In Security Applications: Challenges, Pitfalls, and Lessons Learned
von: Alrawi, Omar, et al.
Veröffentlicht: (2024)
von: Alrawi, Omar, et al.
Veröffentlicht: (2024)
"Tab, Tab, Bug": Security Pitfalls of Next Edit Suggestions in AI-Integrated IDEs
von: Lyu, Yunlong, et al.
Veröffentlicht: (2026)
von: Lyu, Yunlong, et al.
Veröffentlicht: (2026)
MCP-Guard: A Multi-Stage Defense-in-Depth Framework for Securing Model Context Protocol in Agentic AI
von: Xing, Wenpeng, et al.
Veröffentlicht: (2025)
von: Xing, Wenpeng, et al.
Veröffentlicht: (2025)
SecureMCP: A Policy-Enforced LLM Data Access Framework for AIoT Systems via Model Context Protocol
von: Kim, Wonbae, et al.
Veröffentlicht: (2026)
von: Kim, Wonbae, et al.
Veröffentlicht: (2026)
We Urgently Need Privilege Management in MCP: A Measurement of API Usage in MCP Ecosystems
von: Li, Zhihao, et al.
Veröffentlicht: (2025)
von: Li, Zhihao, et al.
Veröffentlicht: (2025)
Prompts Don't Protect: Architectural Enforcement via MCP Proxy for LLM Tool Access Control
von: Uppala, Rohith
Veröffentlicht: (2026)
von: Uppala, Rohith
Veröffentlicht: (2026)
When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents
von: Liu, Shi, et al.
Veröffentlicht: (2026)
von: Liu, Shi, et al.
Veröffentlicht: (2026)
Ähnliche Einträge
-
MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools
von: Tan, Zhuoran, et al.
Veröffentlicht: (2026) -
MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
von: Wang, Zhiqiang, et al.
Veröffentlicht: (2025) -
Auditing MCP Servers for Over-Privileged Tool Capabilities
von: Huang, Charoes, et al.
Veröffentlicht: (2026) -
When MCP Servers Attack: Taxonomy, Feasibility, and Mitigation
von: Zhao, Weibo, et al.
Veröffentlicht: (2025) -
MCPGuard : Automatically Detecting Vulnerabilities in MCP Servers
von: Wang, Bin, et al.
Veröffentlicht: (2025)