- Code injection
- Command injection
- Confused deputy attack
- Context overexposure/leakage
- Context spoofing/integrity violation
- Cross-server tool shadowing/interference
- Data exfiltration via legitimate tools
- Dynamic behavior change (rug pull)
- Excessive permissions (least privilege violation)
- Exposed unnecessary ports/interfaces
- Hardcoded credentials
- Indirect prompt injection
- Insecure direct object references (IDOR)
- Insecure memory/context persistence
- Insufficient authorization/access control
- Lack of observability & auditing
- Lack of transport encryption (TLS)
- Missing/weak authentication
- Model/tool identity misbinding
- Path traversal
- Resource exhaustion
- Sampling vulnerability
- Shadow/unmanaged MCP servers
- Silent redefinition
- Supply chain risks/dependency tampering
- Tool poisoning (malicious instructions in metadata)
- Untrusted third-party MCP servers
Rules Reference
MCP server rules
Vulnerabilities in MCP servers, tools, and their configurations
MCP server rules cover vulnerabilities in MCP servers, tools, and their configurations.