Unsafe by Flow: Uncovering Bidirectional Data-Flow Risks in MCP Ecosystem
Fuente:
arXiv
Saved in:
| Main Authors: | Hou, Xinyi, Zhao, Yanjie, Wang, Haoyu |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Voices from the Frontier: A Comprehensive Analysis of the OpenAI Developer Forum
by: Hou, Xinyi, et al.
Published: (2024)
by: Hou, Xinyi, et al.
Published: (2024)
LLM Applications: Current Paradigms and the Next Frontier
by: Hou, Xinyi, et al.
Published: (2025)
by: Hou, Xinyi, et al.
Published: (2025)
LLM App Store Analysis: A Vision and Roadmap
by: Zhao, Yanjie, et al.
Published: (2024)
by: Zhao, Yanjie, et al.
Published: (2024)
GPTZoo: A Large-scale Dataset of GPTs for the Research Community
by: Hou, Xinyi, et al.
Published: (2024)
by: Hou, Xinyi, et al.
Published: (2024)
Large Language Model Supply Chain: A Research Agenda
by: Wang, Shenao, et al.
Published: (2024)
by: Wang, Shenao, et al.
Published: (2024)
Toward Understanding Bugs in Vector Database Management Systems
by: Xie, Yinglin, et al.
Published: (2025)
by: Xie, Yinglin, et al.
Published: (2025)
GPT Store Mining and Analysis
by: Su, Dongxun, et al.
Published: (2024)
by: Su, Dongxun, et al.
Published: (2024)
Software Engineering for Large Language Models: Research Status, Challenges and the Road Ahead
by: Rao, Hongzhou, et al.
Published: (2025)
by: Rao, Hongzhou, et al.
Published: (2025)
CommitSuite: A Comprehensive Benchmark for Commit Classification and Message Generation
by: Wan, Zirui, et al.
Published: (2026)
by: Wan, Zirui, et al.
Published: (2026)
Bridging Design and Development with Automated Declarative UI Code Generation
by: Zhou, Ting, et al.
Published: (2024)
by: Zhou, Ting, et al.
Published: (2024)
Unveiling the Landscape of LLM Deployment in the Wild: An Empirical Study
by: Hou, Xinyi, et al.
Published: (2025)
by: Hou, Xinyi, et al.
Published: (2025)
Towards Reliable Vector Database Management Systems: A Software Testing Roadmap for 2030
by: Wang, Shenao, et al.
Published: (2025)
by: Wang, Shenao, et al.
Published: (2025)
Same App, Different Behaviors: Uncovering Device-specific Behaviors in Android Apps
by: Dong, Zikan, et al.
Published: (2024)
by: Dong, Zikan, et al.
Published: (2024)
LaQual: A Novel Framework for Automated Evaluation of LLM App Quality
by: Wang, Yan, et al.
Published: (2025)
by: Wang, Yan, et al.
Published: (2025)
WaDec: Decompiling WebAssembly Using Large Language Model
by: She, Xinyu, et al.
Published: (2024)
by: She, Xinyu, et al.
Published: (2024)
CodeMorph: Mitigating Data Leakage in Large Language Model Assessment
by: Rao, Hongzhou, et al.
Published: (2025)
by: Rao, Hongzhou, et al.
Published: (2025)
AUTOVR: Automated UI Exploration for Detecting Sensitive Data Flow Exposures in Virtual Reality Apps
by: Kim, John Y., et al.
Published: (2025)
by: Kim, John Y., et al.
Published: (2025)
Not All RAGs Are Created Equal: A Component-Wise Empirical Study for Software Engineering Tasks
by: Ke, Qiang, et al.
Published: (2026)
by: Ke, Qiang, et al.
Published: (2026)
Models Are Codes: Towards Measuring Malicious Code Poisoning Attacks on Pre-trained Model Hubs
by: Zhao, Jian, et al.
Published: (2024)
by: Zhao, Jian, et al.
Published: (2024)
Agent-Based Software Artifact Evaluation
by: Wu, Zhaonan, et al.
Published: (2026)
by: Wu, Zhaonan, et al.
Published: (2026)
Understanding Large Language Model Supply Chain: Structure, Domain, and Vulnerabilities
by: Hu, Yanzhe, et al.
Published: (2025)
by: Hu, Yanzhe, et al.
Published: (2025)
A Dual-Loop Agent Framework for Automated Vulnerability Reproduction
by: Liu, Bin, et al.
Published: (2026)
by: Liu, Bin, et al.
Published: (2026)
Beyond the Protocol: Unveiling Attack Vectors in the Model Context Protocol (MCP) Ecosystem
by: Song, Hao, et al.
Published: (2025)
by: Song, Hao, et al.
Published: (2025)
Fearless Unsafe. A More User-friendly Document for Unsafe Rust Programming Base on Refined Safety Properties
by: Cui, Mohan, et al.
Published: (2024)
by: Cui, Mohan, et al.
Published: (2024)
LLM Agents for Automated Web Vulnerability Reproduction: Are We There Yet?
by: Liu, Bin, et al.
Published: (2025)
by: Liu, Bin, et al.
Published: (2025)
Gradient-Based Model Fingerprinting for LLM Similarity Detection and Family Classification
by: Wu, Zehao, et al.
Published: (2025)
by: Wu, Zehao, et al.
Published: (2025)
We Urgently Need Privilege Management in MCP: A Measurement of API Usage in MCP Ecosystems
by: Li, Zhihao, et al.
Published: (2025)
by: Li, Zhihao, et al.
Published: (2025)
Adapting Installation Instructions in Rapidly Evolving Software Ecosystems
by: Gao, Haoyu, et al.
Published: (2023)
by: Gao, Haoyu, et al.
Published: (2023)
Large Language Models for Software Engineering: A Systematic Literature Review
by: Hou, Xinyi, et al.
Published: (2023)
by: Hou, Xinyi, et al.
Published: (2023)
CommitShield: Tracking Vulnerability Introduction and Fix in Version Control Systems
by: Wu, Zhaonan, et al.
Published: (2025)
by: Wu, Zhaonan, et al.
Published: (2025)
Towards Robust Detection of Open Source Software Supply Chain Poisoning Attacks in Industry Environments
by: Zheng, Xinyi, et al.
Published: (2024)
by: Zheng, Xinyi, et al.
Published: (2024)
Hidden Licensing Risks in the LLMware Ecosystem
by: Wang, Bo, et al.
Published: (2026)
by: Wang, Bo, et al.
Published: (2026)
Towards a Declarative Agentic Layer for Intelligent Agents in MCP-Based Server Ecosystems
by: Rodriguez-Sanchez, Maria Jesus, et al.
Published: (2026)
by: Rodriguez-Sanchez, Maria Jesus, et al.
Published: (2026)
"Elementary, My Dear Watson." Detecting Malicious Skills via Neuro-Symbolic Reasoning across Heterogeneous Artifacts
by: Wang, Shenao, et al.
Published: (2026)
by: Wang, Shenao, et al.
Published: (2026)
Unsafe and Unused? A History of Utility Code in Mature Open Source Projects
by: Keller, Brandon, et al.
Published: (2026)
by: Keller, Brandon, et al.
Published: (2026)
FlowETL: An Autonomous Example-Driven Pipeline for Data Engineering
by: Di Profio, Mattia, et al.
Published: (2025)
by: Di Profio, Mattia, et al.
Published: (2025)
How Agentic AI Coding Assistants Become the Attacker's Shell
by: Liu, Yue, et al.
Published: (2026)
by: Liu, Yue, et al.
Published: (2026)
"Your AI, My Shell": Demystifying Prompt Injection Attacks on Agentic AI Coding Editors
by: Liu, Yue, et al.
Published: (2025)
by: Liu, Yue, et al.
Published: (2025)
Track and Trace: Automatically Uncovering Cross-chain Transactions in the Multi-blockchain Ecosystems
by: Lin, Dan, et al.
Published: (2025)
by: Lin, Dan, et al.
Published: (2025)
Understanding Software Vulnerabilities in the Maven Ecosystem: Patterns, Timelines, and Risks
by: Rabbi, Md Fazle, et al.
Published: (2025)
by: Rabbi, Md Fazle, et al.
Published: (2025)
Similar Items
-
Voices from the Frontier: A Comprehensive Analysis of the OpenAI Developer Forum
by: Hou, Xinyi, et al.
Published: (2024) -
LLM Applications: Current Paradigms and the Next Frontier
by: Hou, Xinyi, et al.
Published: (2025) -
LLM App Store Analysis: A Vision and Roadmap
by: Zhao, Yanjie, et al.
Published: (2024) -
GPTZoo: A Large-scale Dataset of GPTs for the Research Community
by: Hou, Xinyi, et al.
Published: (2024) -
Large Language Model Supply Chain: A Research Agenda
by: Wang, Shenao, et al.
Published: (2024)