MCP服务器工具投毒审计

原名:auditing-mcp-servers-for-tool-poisoning

使用 Invariant Labs 的 mcp-scan 对 MCP 服务器进行工具投毒、影子工具、rug pulls、SSRF 及未授权暴露的静态/运行时扫描,并结合手动检查与描述锁定。在添加新服务器、审查内部服务器或调查异常行为时使用。

分类
开发提效
版本
v1.0
作者
弈韬(@ra1nzzz)
下载
1
收藏
0
发布
2026-08-18
更新
2026-08-21
TRACE 评分
3.2 / 5

内容概览

Authorized-use-only notice: Auditing MCP servers can connect to and probe live tool endpoints. Only scan servers you own or are authorized to assess. Treat scanned tool descriptions as untrusted input — do not load an unaudited MCP server into a privileged agent. Probing third-party MCP endpoints for SSRF or auth weaknesses without permission may be illegal. The Model Context Protocol (MCP) lets AI agents discover and call external tools advertised by MCP servers. Each tool exposes a name and a natural-language description that the agent's LLM reads before deciding to call it. In early 2025, Invariant Labs disclosed that this description field is an attack surface: a malicious server can embed hidden instructions in a tool's description (a tool poisoning attack , OWASP MCP03:2025 ), and a capable model will silently follow them — exfiltrating files, leaking secrets, or redirecting tool c…

查看 SKILL 详情