Rogue MCP server

An unapproved or impersonating MCP server solicits data, prompts or calls under a trusted-looking tool identity.

01 / Attack path

How the boundary is crossed

A developer accepts a similarly named repository server that asks the agent to upload its workspace inventory.

Attack path and interception point
  1. 01Lower-trust input
  2. 02Attempted instruction
  3. 03Protected action
  4. 04Enforced decision

02 / Containment

Where bounded authority limits the effect

Pin trusted server origin, review package and operator provenance, restrict egress and deny the upload without a task grant.

03 / Failure and evidence

The attacker’s opportunity and the defender’s record

Exploit condition

A familiar tool label causes the client to transfer sensitive data to a different operator.

Evidence to retain

Keep server origin, installation path, tool hash, upload attempt and network result.

04 / Canonical scope

Why this reference stands alone

MCP server trust covers admission criteria; this threat traces a malicious server’s attack path.

Protocol or attack trace

Lookalike server path

Sequence

Unapproved repository MCP server offers expected tool names and asks for workspace inventory upload.

Negative test

Client rejects unknown server origin and egress policy denies upload to its operator.

Primary references

Read the underlying material

Architecture discussion

Choose one consequential action and make its boundary explicit.

Request a Conversation