Mitigating Taint-Style Vulnerabilities in MCP Servers via Security-Aware Tool Descriptions
Yang Shi, Jiaheng Fu, Yihe Huang, Ruixiang Wu, Chengyao Sun, Kaifeng Huang
cs.CR, cs.SE
Submitted: 2026-07-08
Code: https://github.com/en/rest
Project page: https://openai.com/index/hello-gpt-4o
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- Model Context Protocol (MCP) at First Glance: Studying the Security and Maintainability of MCP Servers
- Baseline Defenses for Adversarial Attacks Against Aligned Language Models
- AgentBound: Securing Execution Boundaries of AI Agents
- Improved Techniques for Optimization-Based Jailbreaking on Large Language Models
- MCPToolBench++: A Large Scale AI Agent Model Context Protocol MCP Tool Use Benchmark
- Certifying LLM Safety against Adversarial Prompting
- MCP Guardian: A Security-First Layer for Safeguarding MCP-Based AI System
- Don't believe everything you read: Understanding and Measuring MCP Behavior under Misleading Tool Descriptions
- A Large-Scale Evolvable Dataset for Model Context Protocol Ecosystem and Security Analysis
- AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models
- Jailbreaking ChatGPT via Prompt Engineering: An Empirical Study
- MCPZoo: A Large-Scale Dataset of Runnable Model Context Protocol Servers for AI Agent
- LLM Self Defense: By Self Examination, LLMs Know They Are Being Tricked
- SmoothLLM: Defending Large Language Models Against Jailbreaking Attacks
- MCPMark: A Benchmark for Stress-Testing Realistic and Comprehensive MCP Use
- MCP-Guard: A Multi-Stage Defense-in-Depth Framework for Securing Model Context Protocol in Agentic AI
- Beyond the Protocol: Unveiling Attack Vectors in the Model Context Protocol (MCP) Ecosystem
- Help or Hurdle? Rethinking Model Context Protocol-Augmented Large Language Models
- The Dark Side of Trust: Authority Citation-Driven Jailbreak Attacks on Large Language Models
- MPMA: Preference Manipulation Attack Against Model Context Protocol
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs