MCP Tool Poisoning Attacks

MCP Tool Poisoning Attacks is an MCP server and client demonstration environment that demonstrates security vulnerabilities and threat models involving tool poisoning within the Model Context Protocol ecosystem. The project connects Node.js runtime environments to Anthropic Claude models, specifically testing interactions where tools such as IP lookup utilities manipulate tool definitions or execution flows. Security researchers, AI developers, and penetration testers use this project to examine how compromised tool parameters, schema manipulation, and unexpected outputs affect LLM behavior during automated tool calling. By orchestrating communication between an MCP client and an MCP server over stdio or HTTP Server-Sent Events, the environment allows practitioners to simulate adversarial inputs and assess potential attack surfaces in agent tooling architectures. The system handles requests using the Model Context Protocol TypeScript SDK, letting operators observe prompt handling, tool usage schemas, and raw responses directly through an interactive command-line interface. Users can inspect communication traces and integrate security testing proxies to identify architectural flaws before deploying LLM-based agent pipelines in production settings.

Category: AI & LLM Tooling

Tags: penetration-testing, security research, threat modeling, vulnerability

Visit MCP Tool Poisoning Attacks

How to install and configure MCP Tool Poisoning Attacks

  1. Clone the repository and configure your Anthropic API credentials by creating mcp_client/.env: shell cat << EOF > mcp_client/.env ANTHROPIC_API_KEY=your_anthropic_api_key EOF 2. Configure the server connection in mcp_client/mcpservers.json: json { "mcpServers": { "ipinfo": { "command": "/usr/local/bin/npx", "args": [ "-y", "github:RyosukeDTomita/mcp_tool_poisoning_attacks#main", "ipinfo" ], "env": { "PATH": "/usr/local/bin:/usr/bin:/bin" } } } } 3. Build the Docker container image: shell docker compose build 4. Start the interactive client interface: shell docker compose run -it mcp_client Alternatively, inside a Dev Container, run cd mcp_client, yarn run bundle, and node dist/index.js.

What you can do with MCP Tool Poisoning Attacks

  • Simulating tool poisoning vectors to analyze how Claude 3.5 Haiku responds to manipulated schema definitions and modified tool descriptions. - Testing Model Context Protocol client validation against unexpected or maliciously crafted server responses during automated execution flows. - Auditing local and remote MCP integrations for security misconfigurations using Burp Suite through an SSE proxy connection. - Evaluating defensive guardrails and sanitization layers implemented between external tool providers and large language model agents.

Key facts

  • https://github.com/RyosukeDTomita/mcp_tool_poisoning_attacks
  • AI & LLM Tooling, Security & Compliance
  • penetration-testing, security research, threat modeling, vulnerability

Part of MCP Servers

Related MCP servers

  • MCP Memory Dashboard — MCP Memory Dashboard is an MCP server desktop interface that connects to the MCP Memory Service to provide visual semantic…
  • MCP Manager — MCP Manager is an MCP server management tool that connects directly to your Claude Desktop environment, enabling users to discover,…
  • MCP Lab — MCP Lab is an MCP server development environment designed for building, testing, and debugging custom Model Context Protocol servers integrated…
  • MCP LLM Integration Server — MCP LLM Integration Server is an MCP server that connects local Large Language Model runtimes with Model Context Protocol clients…
  • MCP Neurolora — MCP Neurolora is an MCP server that provides code analysis, code collection, and automated documentation generation using the OpenAI API.…
  • MCP OpenVision — MCP OpenVision is an MCP server that provides image analysis capabilities powered by OpenRouter vision models. It connects client interfaces…

What is MCP Tool Poisoning Attacks?

MCP Tool Poisoning Attacks is a security testing demonstration project built on Node.js and the Model Context Protocol TypeScript SDK. It provides an experimental environment consisting of an MCP client and an MCP server, allowing developers and security researchers to inspect how manipulated tool schemas and outputs affect Anthropic Claude models.

Which requirements are needed to run MCP Tool Poisoning Attacks?

The project requires Node.js version 22 or Docker with Docker Compose installed. You also need a valid Anthropic API key to interact with Claude models like claude-3-5-haiku-20241022. Development containers can also be used inside Visual Studio Code for local setup and testing.

What can MCP Tool Poisoning Attacks do?

The project executes automated queries against tools such as ipinfo while tracing communication exchanges between the client, the server, and Anthropic APIs. It enables users to evaluate threat models, inspect schema poisoning vulnerabilities, and test security assessment tools like Burp Suite using Server-Sent Events configurations.

Which MCP clients work with MCP Tool Poisoning Attacks?

The repository includes its own custom Model Context Protocol client located in the mcp_client directory. Because it implements standard Model Context Protocol specifications, the bundled server definitions can also be integrated into any MCP-compliant client or testing harness that supports command-line execution via npx or SSE transport.

Is MCP Tool Poisoning Attacks open source?

The repository is published on GitHub with an Unlicense open-source badge displayed in its documentation, allowing users to inspect the codebase, run demonstrations, and adapt the security testing framework for their own research and development environments without restrictive licensing terms.

  • AI Tools
  • Categories
  • Industries
  • CLI Coding Agents
  • MCP Servers
  • MCP Categories