about
LLMs with the Model Context Protocol Allow Major Security Exploits (arxiv.org)
2 points by abhisek on Apr 25, 2025 | hide | past | pdf | discuss on HN

In plain words: A popular plug-in standard lets AI assistants call tools to run automated workflows. Top AI models can be tricked through these plug-ins into running malicious code, taking remote control, or stealing credentials, so the team built a free scanner that tests plug-ins for holes.

Abstract · MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits

To reduce development overhead and enable seamless integration between potential components comprising any given generative AI application, the Model Context Protocol (MCP) (Anthropic, 2024) has recently been released and subsequently widely adopted. The MCP is an open protocol that standardizes API calls to large language models (LLMs), data sources, and agentic tools. By connecting multiple MCP servers, each defined with a set of tools, resources, and prompts, users are able to define automated workflows fully driven by LLMs. However, we show that the current MCP design carries a wide range of security risks for end users. In particular, we demonstrate that industry-leading LLMs may be coerced into using MCP tools to compromise an AI developer's system through various attacks, such as malicious code execution, remote access control, and credential theft. To proactively mitigate these and related attacks, we introduce a safety auditing tool, MCPSafetyScanner, the first agentic tool to assess the security of an arbitrary MCP server. MCPScanner uses several agents to (a) automatically determine adversarial samples given an MCP server's tools and resources; (b) search for related vulnerabilities and remediations based on those samples; and (c) generate a security report detailing all findings. Our work highlights serious security issues with general-purpose agentic workflows while also providing a proactive tool to audit MCP server safety and address detected vulnerabilities before deployment. The described MCP server auditing tool, MCPSafetyScanner, is freely available at: https://github.com/johnhalloran321/mcpSafetyScanner

Brandon Radosevich, John Halloran
arXiv:2504.03767 · cs.CR, cs.AI, cs.LG · submitted Apr 2, 2025 · updated Apr 11, 2025
abstract · pdf · html · 27 pages, 21 figures, and 2 Tables. Cleans up the TeX source

add comment on HN