MCP attacks
Adversarial transforms targeting the Model Context Protocol tool layer, including tool poisoning, shadowing, and schema manipulation.
Module: dreadnode.transforms.mcp_attacks
Attacks targeting the Model Context Protocol (MCP) tool layer.
| Transform | Description |
|---|---|
tool_description_poison | Inject malicious instructions into MCP tool descriptions |
cross_server_shadow | Register shadow tools that intercept legitimate tool calls |
rug_pull_payload | Tools that mutate from benign to malicious after trigger |
tool_output_injection | Inject instructions into tool output streams |
tool_squatting | Register tools with confusingly similar names |
resource_amplification | Craft inputs for token consumption DoS |
log_to_leak | Exfiltrate data via logging/telemetry tools |
mcp_sampling_injection | Exploit MCP sampling capability |
cross_server_request_forgery | Forge cross-server tool requests |
schema_poisoning | Poison JSON Schema fields in tool definitions |
ansi_escape_cloaking | Hide instructions in ANSI escape codes |
tool_preference_manipulation | Bias tool selection behavior |
implicit_tool_poison | Implicitly poison tool behavior without obvious injection |
tool_chain_sequential | Sequential tool chain exploitation |
tool_commander | Command injection via tool orchestration |
zero_click_injection | Zero-click injection without user interaction |
calendar_invite_injection | Inject payloads via calendar invite processing |
confused_deputy | Confused deputy attack on tool authorization |
full_schema_poison | Full JSON Schema poisoning of tool definitions |
tool_chain_cost_amplification | Amplify cost via chained tool invocations |
See Transforms for how to apply transforms with any attack.