arXiv AI

Description-Code Inconsistency in Real-world MCP Servers: Measurement, Detection, and Security Implications

arXiv:2606. 04769v1 Announce Type: cross Abstract: The Model Context Protocol (MCP) has emerged as a critical standard empowering Large Language Models (LLMs) to utilize external tools.

arXiv AI
Aug 24

AEGIS: Preventing Cross-Domain Resource Abuse in MCP

AEGIS is a policy enforcement component designed to prevent resource abuse in the Model Context Protocol (MCP), an open‑source JSON‑RPC protocol that allows large language models to interact with external systems via tools. By leveraging large language models to analyze, categorize, and normalize diverse tool invocations across text, images, video, and location modalities, AEGIS provides administrators with fine‑grained safeguards that can be enforced through the Open Policy Agent and ContextForge AI Gateway. This approach enables detection and mitigation of abusive behaviors—such as excessively large search requests or long video calls—while maintaining the flexibility of MCP‑based agent ecosystems.

By Shriti Priya, Teryl Taylor, Frederico Araujo
arXiv AI
Sep 12

No-Box Vulnerability Analysis: Description-only Detection of Indirect Prompt Injection Vulnerabilities in MCP Servers

The paper introduces no‑box vulnerability analysis, a method that detects security flaws without system access or runtime interaction by examining only the functionality metadata of a target. Using this approach, the authors built MCPSEC to audit Model Context Protocol servers for indirect prompt injection vulnerabilities, evaluating it on 20 servers with 177 tools. MCPSEC identified 143 vulnerable tools, achieving 98.9% recall of verified vulnerabilities, outperforming an LLM baseline.

By Zehua Zhang, Jie Hu, Pratham Hegde, Aditya Maheshbhai Gabani, Souradip Nath, Yibo Liu, Siyu Liu, Hongkai Chen, Hulin Wang, Zhuoer Lyu, Chang Zhu, Divij Handa, Yan Shoshitaishvili, Tiffany Bao, Ruoyu Wang, Adam Doupe