01 / Attack path
How the boundary is crossed
A developer accepts a similarly named repository server that asks the agent to upload its workspace inventory.
- 01Lower-trust input
- 02Attempted instruction
- 03Protected action
- 04Enforced decision
02 / Containment
Where bounded authority limits the effect
Pin trusted server origin, review package and operator provenance, restrict egress and deny the upload without a task grant.
03 / Failure and evidence
The attacker’s opportunity and the defender’s record
A familiar tool label causes the client to transfer sensitive data to a different operator.
Keep server origin, installation path, tool hash, upload attempt and network result.
04 / Canonical scope
Why this reference stands alone
MCP server trust covers admission criteria; this threat traces a malicious server’s attack path.
Protocol or attack trace
Lookalike server path
Unapproved repository MCP server offers expected tool names and asks for workspace inventory upload.
Client rejects unknown server origin and egress policy denies upload to its operator.
Primary references