Skip to content

MCP attacks

Adversarial transforms targeting the Model Context Protocol tool layer, including tool poisoning, shadowing, and schema manipulation.

Module: dreadnode.transforms.mcp_attacks

Attacks targeting the Model Context Protocol (MCP) tool layer.

TransformDescription
tool_description_poisonInject malicious instructions into MCP tool descriptions
cross_server_shadowRegister shadow tools that intercept legitimate tool calls
rug_pull_payloadTools that mutate from benign to malicious after trigger
tool_output_injectionInject instructions into tool output streams
tool_squattingRegister tools with confusingly similar names
resource_amplificationCraft inputs for token consumption DoS
log_to_leakExfiltrate data via logging/telemetry tools
mcp_sampling_injectionExploit MCP sampling capability
cross_server_request_forgeryForge cross-server tool requests
schema_poisoningPoison JSON Schema fields in tool definitions
ansi_escape_cloakingHide instructions in ANSI escape codes
tool_preference_manipulationBias tool selection behavior
implicit_tool_poisonImplicitly poison tool behavior without obvious injection
tool_chain_sequentialSequential tool chain exploitation
tool_commanderCommand injection via tool orchestration
zero_click_injectionZero-click injection without user interaction
calendar_invite_injectionInject payloads via calendar invite processing
confused_deputyConfused deputy attack on tool authorization
full_schema_poisonFull JSON Schema poisoning of tool definitions
tool_chain_cost_amplificationAmplify cost via chained tool invocations

See Transforms for how to apply transforms with any attack.