MCP Tool Poisoning Attacks is an MCP server and client demonstration environment that demonstrates security vulnerabilities and threat models involving tool poisoning within the Model Context Protocol ecosystem. The project connects Node.js runtime environments to Anthropic Claude models, specifically testing interactions where tools such as IP lookup utilities manipulate tool definitions or execution flows. Security researchers, AI developers, and penetration testers use this project to examine how compromised tool parameters, schema manipulation, and unexpected outputs affect LLM behavior during automated tool calling. By orchestrating communication between an MCP client and an MCP server over stdio or HTTP Server-Sent Events, the environment allows practitioners to simulate adversarial inputs and assess potential attack surfaces in agent tooling architectures. The system handles requests using the Model Context Protocol TypeScript SDK, letting operators observe prompt handling, tool usage schemas, and raw responses directly through an interactive command-line interface. Users can inspect communication traces and integrate security testing proxies to identify architectural flaws before deploying LLM-based agent pipelines in production settings.
Category: AI & LLM Tooling
Tags: penetration-testing, security research, threat modeling, vulnerability
Visit MCP Tool Poisoning Attacks
mcp_client/.env: shell cat << EOF > mcp_client/.env ANTHROPIC_API_KEY=your_anthropic_api_key EOF 2. Configure the server connection in mcp_client/mcpservers.json: json { "mcpServers": { "ipinfo": { "command": "/usr/local/bin/npx", "args": [ "-y", "github:RyosukeDTomita/mcp_tool_poisoning_attacks#main", "ipinfo" ], "env": { "PATH": "/usr/local/bin:/usr/bin:/bin" } } } } 3. Build the Docker container image: shell docker compose build 4. Start the interactive client interface: shell docker compose run -it mcp_client Alternatively, inside a Dev Container, run cd mcp_client, yarn run bundle, and node dist/index.js.Part of MCP Servers
MCP Tool Poisoning Attacks is a security testing demonstration project built on Node.js and the Model Context Protocol TypeScript SDK. It provides an experimental environment consisting of an MCP client and an MCP server, allowing developers and security researchers to inspect how manipulated tool schemas and outputs affect Anthropic Claude models.
The project requires Node.js version 22 or Docker with Docker Compose installed. You also need a valid Anthropic API key to interact with Claude models like claude-3-5-haiku-20241022. Development containers can also be used inside Visual Studio Code for local setup and testing.
The project executes automated queries against tools such as ipinfo while tracing communication exchanges between the client, the server, and Anthropic APIs. It enables users to evaluate threat models, inspect schema poisoning vulnerabilities, and test security assessment tools like Burp Suite using Server-Sent Events configurations.
The repository includes its own custom Model Context Protocol client located in the mcp_client directory. Because it implements standard Model Context Protocol specifications, the bundled server definitions can also be integrated into any MCP-compliant client or testing harness that supports command-line execution via npx or SSE transport.
The repository is published on GitHub with an Unlicense open-source badge displayed in its documentation, allowing users to inspect the codebase, run demonstrations, and adapt the security testing framework for their own research and development environments without restrictive licensing terms.