Skills
MCPSEC flags indirect-prompt-injection-prone MCP tools from registration metadata alone at 98.9% recall
The 'no-box' method reads only the tool descriptions a server exposes at registration and hypothesizes injection vulnerabilities that would hold for any implementation of that behavior. Across 20 widely deployed MCP servers with 177 tools, it caught 94 of 95 human-confirmed vulnerable tools, against 80 for an LLM baseline. The trade-off is false positives: it flagged 143 tools in total. The approach works as a pre-install filter. Any tool whose description says it returns third-party content, such as web pages, emails or issues, should be treated as an injection entry point before you connect the server.
↳ Follow the thread