Pith. sign in

Paper Citation Record · LEDGER

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers

As of 1 August 2026, this Paper Citation Record lists 78 of 78 outbound references and 6 inbound Pith citation observations for arXiv:2604.01905.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2604.01905 v2

Coverage vector

measured 78 of 78 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-05-21T10:41:17.307952Z

measured 84 of 84 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-01T06:32:01.292127+00:00

measured 6 of 6 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-07-12T17:06:32.429160Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-07-02T14:37:03.245592Z

Reference resolution

78 of 78 outbound references displayed

  • verified exact25
  • verified fuzzy47
  • unresolved6
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 2192dcf6-10b3-41a4-8788-9a515de1430d · outbound

This paper cites The work-averse cyberattacker model: theory and evidence from two million attack signatures.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers The work-averse cyberattacker model: theory and evidence from two million attack signatures

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.928011Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:2172c9b8cf0539f7d3bae7bba0feab15126edc6fce1e56e103b321a3c423e40e

Observation 5b076f73-67fc-4324-a716-f5057198580e · outbound

This paper cites an unresolved cited work.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Unresolved cited work

Reference 2

Resolution
unresolved
raw_fallback, observed 2026-05-21T10:45:00.760560Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:61c9e7395a21a29b860885eadf69a49310cc99de1f64e0f654fbd37ddf8c593a

Observation d974657e-62c4-491a-bb1f-cda08b211498 · outbound

This paper cites Introducing the model context protocol.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Introducing the model context protocol

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.752549Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:0ac5e0b170a52cf1f4f81bbe68aac98ae6d8e860c3f98ffe27466a974a0fcc05

Observation 190d6d1c-89dd-4dd9-8611-b51cacb5e869 · outbound

This paper cites ETDI: Mitigating Tool Squatting and Rug Pull Attacks in Model Context Protocol (MCP) by using OAuth-Enhanced Tool Definitions and Policy-Based Access Control.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers ETDI: Mitigating Tool Squatting and Rug Pull Attacks in Model Context Protocol (MCP) by using OAuth-Enhanced Tool Definitions and Policy-Based Access Control

Reference 4

Resolution
verified exact
arxiv_id, observed 2026-05-21T10:44:07.968019Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:1d03fb18f50c1d8e9d8d3e88bb50f5a596f69ea4a55be5038f4d90701f70f48f

Observation 04dcebb7-a223-47f7-a693-2f6f315df753 · outbound

This paper cites AgentBound: Securing Execution Boundaries of AI Agents.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers AgentBound: Securing Execution Boundaries of AI Agents

Reference 5

Resolution
verified exact
local_arxiv, observed 2026-05-21T10:44:07.980759Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:d6b62f9de75a1e437bc92bbe3f4ad28c0860bf15498d172971aba16d46e8705c

Observation cf88cb01-1c1d-41f8-a5f7-9ceda4af6dff · outbound

This paper cites an unresolved cited work.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Unresolved cited work

Reference 6

Resolution
unresolved
raw_fallback, observed 2026-05-21T10:45:00.750200Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:07f699e0250316723cf5a6eb4c82df1509c9977f7d897020d20ff498731d14b3

Observation 6cb1a0d0-1510-4288-ba2b-5c8f6bcf1e9d · outbound

This paper cites Connect claude code to tools via mcp.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Connect claude code to tools via mcp

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.758296Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:3537627da2241b2e292af602c1ae0e139c25a34529166ea88162c168bc53fc04

Observation 1057eb7c-15da-4fd6-9555-dacb39523cd1 · outbound

This paper cites Introducing claude 4.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Introducing claude 4

Reference 8

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.807955Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:382529190ef61f0faf2efb375df4cc40d741d24e454524581f39306966355615

Observation 097d7d9f-6d32-4edd-adf1-bb0db9005fa8 · outbound

This paper cites Introducing claude sonnet 4.5.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Introducing claude sonnet 4.5

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.916168Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:18ae3968455fcfcebab813cb1a7045d1168ac2efb1a5893f2bd7b67e625d8a08

Observation ed718e72-705b-4a03-a35c-85707fc2cddc · outbound

This paper cites an unresolved cited work.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Unresolved cited work

Reference 10

Resolution
unresolved
raw_fallback, observed 2026-05-21T10:45:00.805756Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:d849cb7e9cbc5c8c07ffa79a7667e73c4f47ebe17d32bf14cd1c9dc7976dfea2

Observation f494db30-0fca-4313-b980-73ed35f981e8 · outbound

This paper cites Cursor agent.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Cursor agent

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.755744Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:dd7f79679d34670a27ca04b3b21974863f66c1bb4c199c84cd02b3621dc7ffa4

Observation b99abbb5-bf61-4b32-bd27-db743fbdb143 · outbound

This paper cites Cursor directory - cursor rules & mcp servers.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Cursor directory - cursor rules & mcp servers

Reference 12

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.801406Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:bb166ddeab262f56f4a5a59f7d995eda024a7d706dba9a19c9f456c5b6c12f45

Observation e6acea98-fcab-401f-8d3f-3c563c60a920 · outbound

This paper cites Model context protocol (mcp) | cursor docs.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Model context protocol (mcp) | cursor docs

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.767631Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:e18ec47d3c3a98a2a3a0427be9924d108c149257348124936204e0dd72c945d8

Observation 9e414ee2-0943-40d8-a528-8baa48fdae2a · outbound

This paper cites Deepseek-v3.1.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Deepseek-v3.1

Reference 14

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.813971Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:13af5d67998dd4dc98a0bc09cde45bfe7255bf097e9da3fe2eaea90ed0a01631

Observation d1f617fa-f6b7-4730-92bd-e13963270dbb · outbound

This paper cites A survey of agent interoperability protocols: Model Context Protocol (MCP), Agent Communication Protocol (ACP), Agent-to-Agent Protocol (A2A), and Agent Network Protocol (ANP).

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers A survey of agent interoperability protocols: Model Context Protocol (MCP), Agent Communication Protocol (ACP), Agent-to-Agent Protocol (A2A), and Agent Network Protocol (ANP)

Reference 15

Resolution
verified exact
arxiv_id, observed 2026-05-21T10:44:07.939641Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:9256f9adc81f0d52075e5f8e42e339e011f1efbce2e3a75129213332edddfc50

Observation 480a69b4-2b84-4ec8-a628-112915abefca · outbound

This paper cites We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 16

Resolution
verified exact
arxiv_id, observed 2026-05-21T10:44:07.943736Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:3498dc3d4f60709957ba6e0a047d8f2797694f5cdcaf3096ad72368eacbdbcc0

Observation c8f490d6-4eca-43dc-89e4-0ed0090e3984 · outbound

This paper cites Enhanced prompting framework for code summarization with large language models.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Enhanced prompting framework for code summarization with large language models

Reference 17

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.765195Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:4a812a825e9cf8316539b786a10d2298ff9d6e1f98c97bd520e9622b98c14f21

Observation 0bd7ea9f-9fc7-4e64-9355-7744952aedcb · outbound

This paper cites Mcp json configuration.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Mcp json configuration

Reference 18

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.792777Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:14fa922077826e2459cdbd983f800877ca500b5aee4003c53d3e407eabcc2d66

Observation 0e6f0b64-84eb-4c0e-ab11-966dc6d1abaa · outbound

This paper cites Trae Agent: An LLM-based Agent for Software Engineering with Test-time Scaling.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Trae Agent: An LLM-based Agent for Software Engineering with Test-time Scaling

Reference 19

Resolution
verified exact
arxiv_id, observed 2026-05-21T10:44:07.953210Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:30b33ebe9fef90b93014cf8a80b21e70624e85bf029957b8178c6eac59a5f44f

Observation f665a585-cf79-412e-a57f-bace9f2e3319 · outbound

This paper cites Malguard: towards real-time, accurate, and actionable detection of malicious packages in pypi ecosystem.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Malguard: towards real-time, accurate, and actionable detection of malicious packages in pypi ecosystem

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.893174Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:b59332e6c9feba7acae7d56cfc5339edc62240d520812d54b6ab85f61eb16c97

Observation 69abd670-8d92-4cf1-8a7f-2fa323291ef6 · outbound

This paper cites Github copilot·your ai pair programmer.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Github copilot·your ai pair programmer

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.816443Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:3705f620a677b4cbb426f8dd99fc24d8a79a5f95b90eddaf3d624355d5ad5f45

Observation af9ac2a0-9b08-41b6-a2b1-9f38f37df736 · outbound

This paper cites Extending github copilot coding agent with the model context protocol (mcp).

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Extending github copilot coding agent with the model context protocol (mcp)

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.905761Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:ab24eaa272681483ed5574fe0a7cb4f59150df7700cdc2ea2c10fbdb4faca0ec

Observation cc436108-e240-47ab-b1e5-7ecb56512c3a · outbound

This paper cites Popular mcp servers.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Popular mcp servers

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.831449Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:90befa268425460944385fe96627d157efef34d400237dbc6943f0eca7527de2

Observation 49556769-5d8e-43f0-b056-6a58c97919fe · outbound

This paper cites Gemini 3.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Gemini 3

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.883813Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:c7b6cffd8cfdfb7f7c414a1b86200a24aff9f6958190cd0641af2a8dfd59e729

Observation c6af10fd-2023-4290-93af-dd3a90c10fac · outbound

This paper cites Gtfobins.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Gtfobins

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.880459Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:3b15e48de7edf5eecfab8af60129d6b00712c72abaade2dc59d4ace49be19bdc

Observation 237775eb-2dfe-45c3-8314-d8a33dae2ce4 · outbound

This paper cites A measurement study of model context protocol ecosystem.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers A measurement study of model context protocol ecosystem

Reference 26

Resolution
verified exact
arxiv_id, observed 2026-05-21T10:44:07.942888Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:4f015a4ac5b126617ace7cb1ba1d2604edf2a91d2173b2bbf92db8463586e76f

Observation f4c4f5bd-186f-43eb-afda-a6d6de454b4f · outbound

This paper cites Large language model based multi-agents: A survey of progress and challenges.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Large language model based multi-agents: A survey of progress and challenges

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.887281Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:189614a4088b3344e71950aa414aa79c15a45c038ef953c043bcaa9dc8f932d0

Observation f42ca10a-0c9e-47a8-b160-17a65403343b · outbound

This paper cites An empirical study of malicious code in pypi ecosystem.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers An empirical study of malicious code in pypi ecosystem

Reference 28

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.822770Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:5cb3c531a8702de61fc5171fa10c9bd276642b21b98a35e2f67751fa624eb7aa

Observation 557f52d1-9262-408b-aa0d-617d2aa011a9 · outbound

This paper cites MCPXKIT: The Unified Toolkit for Analyzing Model Context Protocol Security.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers MCPXKIT: The Unified Toolkit for Analyzing Model Context Protocol Security

Reference 29

Resolution
verified exact
arxiv_id, observed 2026-05-26T03:04:03.989565Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:d47ca05f1a3c86f0572edf3579540dfd53b1d4db305ceeed37969690ab448632

Observation 4bf2cacd-5007-4fee-a159-f45a7cbbd2e2 · outbound

This paper cites damn-vulnerable-mcp-server.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers damn-vulnerable-mcp-server

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.874287Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:cbbcce7a0f3d403bbdb9a4c7014dc70a9abc702cd4e6f54478abce40f02bd9a5

Observation 1a6ac7e8-b7f1-4bf8-8a9f-b7abfae41d19 · outbound

This paper cites Model Context Protocol (MCP) at First Glance: Studying the Security and Maintainability of MCP Servers.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Model Context Protocol (MCP) at First Glance: Studying the Security and Maintainability of MCP Servers

Reference 31

Resolution
verified exact
local_arxiv, observed 2026-05-21T10:44:07.927214Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:131cff5d8677b3884f8c4979f3b241753d2a163a1c49c01984c0af6b54211f66

Observation bb4db277-4916-498e-a4bf-bc350d7021dc · outbound

This paper cites Model Context Protocol (MCP) Tool Descriptions Are Smelly! Towards Improving AI Agent Efficiency with Augmented MCP Tool Descriptions.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Model Context Protocol (MCP) Tool Descriptions Are Smelly! Towards Improving AI Agent Efficiency with Augmented MCP Tool Descriptions

Reference 32

Resolution
verified exact
arxiv_id, observed 2026-06-02T02:04:14.693990Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:6b2db7ed2a585f026ba747a3eb96b4777d55f1aaa2fc56b0cc5340b521539db9

Observation 374bd470-144f-4659-af45-96c6bce02cdd · outbound

This paper cites Automatic red teaming llm-based agents with model context protocol tools.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Automatic red teaming llm-based agents with model context protocol tools

Reference 33

Resolution
verified exact
arxiv_id, observed 2026-05-21T10:44:07.957746Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:d046a5b29468f75c3da91da4c396ac92aaad8b97a675e315b5c4ed946bbc23e9

Observation ad3df134-ad3c-4cb7-b2e8-102e5387e8b1 · outbound

This paper cites Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions

Reference 34

Resolution
verified exact
local_arxiv, observed 2026-05-21T10:44:07.990087Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:00ebabb7385c18cde6872c7163b3180f8fe8effa4e9981bab00a799bc8fd4275

Observation 0b855f7a-2327-449f-8479-aeb112e0fd22 · outbound

This paper cites Donapi: Malicious npm packages detector using behavior sequence knowledge mapping.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Donapi: Malicious npm packages detector using behavior sequence knowledge mapping

Reference 35

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.924647Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:a2511195b7607851e45203de20acd7cca53d0047f53968e41704d06a4ec71681

Observation e5336804-7bf5-4983-8063-e0585855947a · outbound

This paper cites Spiderscan: Practical detection of malicious npm packages based on graph-based behavior modeling and matching.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Spiderscan: Practical detection of malicious npm packages based on graph-based behavior modeling and matching

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.910147Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:4a0ad8cb788ddc81668dab7574905ebc1ecd6346a3c6760d86e06a61d15ffe71

Observation 940bbfca-d0a4-4598-ac5c-25ca81a69d91 · outbound

This paper cites Profmal: Detecting malicious npm packages by the synergy between static and dynamic analysis.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Profmal: Detecting malicious npm packages by the synergy between static and dynamic analysis

Reference 37

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.810239Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:14c4e2a4f4217db0f9cedca46ec73a38896ea8ab3f498faf74ceb7dd6802e524

Observation ac8dbf75-a1bd-4f2f-a7ae-1b499f488392 · outbound

This paper cites Mcp security notification: Tool poisoning attacks.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Mcp security notification: Tool poisoning attacks

Reference 38

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.871660Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:2f3b8a49eb2cd1aa9cf52cce8bc9c7b8c4c596e2a4bbd95c6988429c72711076

Observation 2cc996c9-c7d4-47d4-82f5-841680381f60 · outbound

This paper cites Whatsapp mcp exploited: Exfiltrating your message history via mcp.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Whatsapp mcp exploited: Exfiltrating your message history via mcp

Reference 39

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.799035Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:07033812d234c1be0284cd608d5afb9682cb68243497851e712607a656c2e90e

Observation b93c7ea2-0e9e-4075-832d-76a49a6ac8d3 · outbound

This paper cites mcp-scan.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers mcp-scan

Reference 40

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.901534Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:b4b6620fc4bb3ef1ef559d5a65397f6b1361cd5780ed0f3b9bbeff3b88364e0d

Observation 8faed80e-5767-4f80-b2a6-42a48012c9d2 · outbound

This paper cites Mcip: Protecting mcp safety via model contextual integrity protocol.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Mcip: Protecting mcp safety via model contextual integrity protocol

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.773620Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:012816c32f1922eccf155f09007a9776add3abdf99af1907dcb213da286fa9ff

Observation 5ff15277-1224-4569-b4e6-580f7e8257f9 · outbound

This paper cites Joern - the bug hunter’s workbench.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Joern - the bug hunter’s workbench

Reference 42

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.868191Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:d1cc13946ec2ddae80492250462aba5783c2db24ee198d379ef680671c4a1960

Observation f5d8d013-bfe6-4b7a-aeb6-e7e98ec95b30 · outbound

This paper cites 3 malicious mcp servers found on pypi.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers 3 malicious mcp servers found on pypi

Reference 43

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.762918Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:72f104b93424d2dc9098ee1eb01286c3f24db44c257ec7093cae686beb1dc1e3

Observation d4a75edc-5d23-48c4-90e8-3ccd6f41ffae · outbound

This paper cites MCP Guardian: A Security-First Layer for Safeguarding MCP-Based AI System.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers MCP Guardian: A Security-First Layer for Safeguarding MCP-Based AI System

Reference 44

Resolution
verified exact
arxiv_id, observed 2026-05-21T10:44:07.990066Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:6e7741a22992f3a4c106531bea7b9bd6b4926bdcb8fa7b7fb48967ac3c669da9

Observation 0511f971-afff-4b99-837e-03200e6a44f2 · outbound

This paper cites First malicious mcp server found stealing emails in rogue postmark-mcp package.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers First malicious mcp server found stealing emails in rogue postmark-mcp package

Reference 45

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.825023Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:69008c7e0e1df2b6914fb0bb8abe26e5efddf73e172ad6db4ff2cea89b8ff18a

Observation e0fe6fa6-cc55-4afd-a851-023ccc31768a · outbound

This paper cites The platform for reliable agents.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers The platform for reliable agents

Reference 46

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.770378Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:78b2025a4e5529b7f3cceae658e9dc34c8aebe99dbdc75c6bad5488579defe7d

Observation fd25793d-df60-426a-857d-d809ff0e2cce · outbound

This paper cites We urgently need privilege management in mcp: A measurement of api usage in mcp ecosystems.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers We urgently need privilege management in mcp: A measurement of api usage in mcp ecosystems

Reference 47

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.865519Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:ba559832be9290d5f95cd8d212c6789410dd945f629f3664e79ff344b113f8fe

Observation 7caaed62-d043-489e-922f-6ac0a34b1ef2 · outbound

This paper cites Getting started with model context protocol part 2: Prompts and resources.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Getting started with model context protocol part 2: Prompts and resources

Reference 48

Resolution
verified exact
arxiv_id, observed 2026-05-21T10:44:07.994066Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:ec3c67bf466b234e04c1c23d0a3e27376b4252fd1a0ec8ef0b8518c66276a3df

Observation f3df08c5-f9f8-4071-8816-02bdfaf7e621 · outbound

This paper cites From large to mammoth: A comparative evaluation of large language models in vulnerability detection.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers From large to mammoth: A comparative evaluation of large language models in vulnerability detection

Reference 49

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.862399Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:532fbcae326762bd62670b298bb8eed21c5fbf2bc01ad7cb1d2cffabfed5637d

Observation b9c9b25d-6e4f-4b2f-881a-4d81076ef73a · outbound

This paper cites an unresolved cited work.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Unresolved cited work

Reference 50

Resolution
unresolved
raw_fallback, observed 2026-05-21T10:45:00.854014Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:ff9f0efc2f8257344e94e8aecb9eb424e2f942be47093f1bc5bcd5c9473e379c

Observation 508818d3-bec9-4a0f-a9e8-bef50aba2370 · outbound

This paper cites Model context protocol servers.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Model context protocol servers

Reference 51

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.776123Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:9ecc99bc2fcbe33612d0b2644a0c81d20cef19049dce114394415f7cef00dc88

Observation 20451973-ffc5-4e66-8a24-69b90a79aa7e · outbound

This paper cites Enterprise-Grade Security for the Model Context Protocol (MCP): Frameworks and Mitigation Strategies.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Enterprise-Grade Security for the Model Context Protocol (MCP): Frameworks and Mitigation Strategies

Reference 52

Resolution
verified exact
arxiv_id, observed 2026-05-21T10:44:07.986165Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:af37b1d5a1214a14ca2a0b21f9f896154693e5c73f2eaa6067e4d7f3a1619e20

Observation 6b597d75-0048-4073-80d3-d50b82301b43 · outbound

This paper cites Securing GenAI Multi-Agent Systems Against Tool Squatting: A Zero Trust Registry-Based Approach.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Securing GenAI Multi-Agent Systems Against Tool Squatting: A Zero Trust Registry-Based Approach

Reference 53

Resolution
verified exact
arxiv_id, observed 2026-05-21T10:44:08.025728Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:09156b20203c48e4c73a714e7fca9ff568ca7dabf4ecc7af755d8d02f9a72b29

Observation 759924c2-7e4d-4e2e-9f4f-f608a538c621 · outbound

This paper cites Backstabber’s knife collection: A review of open source software supply chain attacks.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Backstabber’s knife collection: A review of open source software supply chain attacks

Reference 54

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.851444Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:be8f787b704c5b6f47e7fb2fdfa3774cbacb0a596680ad87f4741a13ac90e285

Observation 33028c8a-beb2-48a2-8cee-d7f9e4289644 · outbound

This paper cites Function calling.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Function calling

Reference 55

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.782142Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:300885478b136419f42482ae58b7c58e554a61919fdb6b4179494c1d78ca3db3

Observation 4378cc40-2157-4422-8e98-0704b9f3d1bf · outbound

This paper cites Introducing gpt-5.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Introducing gpt-5

Reference 56

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.889634Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:d9a2139efe992d5fb6c010e3273cdb557e7cd27f554daa28a911825cd3c25c44

Observation e82346e1-0c7e-4bc3-933c-d07b4ff14b9b · outbound

This paper cites A distributed vulnerability database for open source.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers A distributed vulnerability database for open source

Reference 57

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.788211Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:315e62df63751ebf4843cc8d0042297b8a62621c930a9de99cee6318216cbdad

Observation 55bd9afb-305a-4d82-9544-efcec9c496b3 · outbound

This paper cites Mcp server directory.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Mcp server directory

Reference 58

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.849001Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:31afbac2b168f33555fe53061b7ce881253ede1765a32d09be6c7451717bb03a

Observation c9c1a46d-977e-4608-a790-68b1f28e8570 · outbound

This paper cites Toolllm: Facilitating large language models to master 16000+ real-world apis.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Toolllm: Facilitating large language models to master 16000+ real-world apis

Reference 59

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.778559Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:4371152034461f75116779becb3aa71d5c8c6125003eb96c754a3cf11a04ff11

Observation 78cab1b6-7448-4f6e-b6e2-fb4641a7a53e · outbound

This paper cites MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits

Reference 60

Resolution
verified exact
arxiv_id, observed 2026-05-21T10:44:07.977009Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:e9734e1a889dfa58787b0f5bf2e3f5566aa578045992f299114df1ccf6ecae42

Observation 03eaeeeb-163c-471c-bca4-1cb5fd48aaa5 · outbound

This paper cites A survey on model context protocol: Architecture, state-of-the-art, challenges and future directions.Authorea Preprints.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers A survey on model context protocol: Architecture, state-of-the-art, challenges and future directions.Authorea Preprints

Reference 61

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.846438Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:7f0a3ac0ae74b5d80defa77f6d7be7fd030443400ebc56c5d155a3d234286593

Observation 54548b34-58b5-414b-be75-0152c56d4a7f · outbound

This paper cites Benefits of using mcp over traditional integration methods.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Benefits of using mcp over traditional integration methods

Reference 62

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.795391Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:e1d27ffaf1164805c3807627bda9a6dc601e0d3c04b67f8015f3821cb9f9d6b4

Observation 6f94083b-5363-4c64-ae68-4c3e9d4c7b5d · outbound

This paper cites PromptArmor: Simple yet Effective Prompt Injection Defenses.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers PromptArmor: Simple yet Effective Prompt Injection Defenses

Reference 63

Resolution
verified exact
arxiv_id, observed 2026-05-21T10:44:07.917743Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:71ffe4f86ff03174f0005c923bf0afb6202d84663a55cf6e5a92d6ed5a35485b

Observation 8e9cd14e-7176-4805-9696-98998c5cc01f · outbound

This paper cites Smithery - turn scattered context into skills for ai.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Smithery - turn scattered context into skills for ai

Reference 64

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.843775Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:19941cf12881193847db72e1b88e03472c3d5bd410a55c52ce72ff22bea0d9b6

Observation 5cd76137-761b-4c22-b3bd-7ca4b19648dc · outbound

This paper cites Beyond the Protocol: Unveiling Attack Vectors in the Model Context Protocol (MCP) Ecosystem.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Beyond the Protocol: Unveiling Attack Vectors in the Model Context Protocol (MCP) Ecosystem

Reference 65

Resolution
verified exact
arxiv_id, observed 2026-05-21T10:44:07.947643Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:c2b62322ba72483e424b5170d03a4504d885e7e0c8cdae1ad8d4ed7c277ba639

Observation 59d0a1f6-8ca3-4865-8682-9bfef1b3e135 · outbound

This paper cites Ai-infra-guard.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Ai-infra-guard

Reference 66

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.790557Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:1a0823c6e96bdf0e6f46be78e782e7f190258ee76385448ea032bfceac5b8cfd

Observation a6b45c99-62b5-4144-b3e0-40c6c33ad2b6 · outbound

This paper cites Mcpguard: Automatically detecting vulnerabilities in mcp servers.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Mcpguard: Automatically detecting vulnerabilities in mcp servers

Reference 67

Resolution
verified exact
arxiv_id, observed 2026-05-21T10:44:07.917949Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:866f8e63fca6a8c5fc41f26c29306db8eb3fd7b0b1972ce354d07bf0d8307755

Observation 7f0717bd-4da2-4e1c-926b-f2302777d49c · outbound

This paper cites Self-instruct: Aligning language models with self-generated instructions.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Self-instruct: Aligning language models with self-generated instructions

Reference 68

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.827898Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:cc59a7a99bfb0eaa2d2b46a3ecd6064cd5e60984b51263507a0b73c68aaf3245

Observation 25d30a3c-c9d9-4a3f-97f2-ada6f168dcee · outbound

This paper cites Mpma: Preference manipulation attack against model context protocol.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Mpma: Preference manipulation attack against model context protocol

Reference 69

Resolution
verified exact
arxiv_id, observed 2026-05-21T10:44:07.998297Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:f9e517383e08a5980a46eb77841032c54eaa755eaaa6b44360c1e15105414363

Observation a9728051-ec2e-4682-b9db-977ce9237f25 · outbound

This paper cites Mcp-guard: A defense framework for model context protocol integrity in large language model applications.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Mcp-guard: A defense framework for model context protocol integrity in large language model applications

Reference 70

Resolution
verified exact
arxiv_id, observed 2026-05-21T10:44:07.909577Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:0c10a847e935868d1e69cb1bf63b6c71d628c5388dfbae029197866d611173d8

Observation 38b68d2c-9635-452b-a294-4648e9dbd875 · outbound

This paper cites A Survey of AI Agent Protocols.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers A Survey of AI Agent Protocols

Reference 71

Resolution
verified exact
arxiv_id, observed 2026-05-21T10:44:07.958043Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:d3cf2c69dd0ea9d745fb2ac305b1fc67cd29da5c3cfb1683c7496329e1282762

Observation c36df13c-fe5a-4d3c-a71d-1f949f3eaf95 · outbound

This paper cites Mcpsecbench: A systematic security benchmark and playground for testing model context protocols.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Mcpsecbench: A systematic security benchmark and playground for testing model context protocols

Reference 72

Resolution
verified exact
arxiv_id, observed 2026-05-21T10:44:08.021580Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:f3d6c1e8359a619df30107daba501bf570e91b53cf6e26fabf4a96367808a667

Observation 244e3ed8-d059-4794-890c-d539d3db37c5 · outbound

This paper cites an unresolved cited work.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Unresolved cited work

Reference 73

Resolution
unresolved
raw_fallback, observed 2026-05-21T10:45:00.820414Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:a701a37a9de0cd3f651f16576d4579a9f02e065db9d6fb93c84650a8fa709709

Observation d2fff69f-aa24-4e05-922f-1dd85121f632 · outbound

This paper cites Williams.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Williams

Reference 74

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.840781Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:47324d4b969291507259ade73ec69b817e07545eaecef44f178cf3876bef3062

Observation 0c0f68e9-a624-4852-9491-e7d14c8b7d0f · outbound

This paper cites an unresolved cited work.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Unresolved cited work

Reference 75

Resolution
unresolved
raw_fallback, observed 2026-05-21T10:45:00.836062Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:190a14335d4790c2ea01e5dc337a9003c7502a1992f51755479893f75eefd146

Observation d49b879c-3882-4b6c-850e-eeb3ae5ff61a · outbound

This paper cites Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP Ecosystem.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP Ecosystem

Reference 76

Resolution
verified exact
local_arxiv, observed 2026-05-21T10:44:07.972874Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:53a734eb44797a6cf13f4ccd8bcddcaf84907a4f2708fc170cb5a587df0df97f

Observation e4c9d553-941b-4b56-91ab-ea72816738bf · outbound

This paper cites When mcp servers attack: Taxonomy, feasibility, and mitigation.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers When mcp servers attack: Taxonomy, feasibility, and mitigation

Reference 77

Resolution
verified exact
arxiv_id, observed 2026-05-21T10:44:07.947806Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:c57e489ccb65c4db22c4529197edbd3b19964266df3f9094f08020bf21e97bc6

Observation feffcdfc-5d51-453c-be19-2ad36cfab178 · outbound

This paper cites –” in the “ID.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers –” in the “ID

Reference 78

Resolution
verified fuzzy
raw_fallback, observed 2026-05-21T10:45:00.833954Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:455882452aed24f976363bb2d03e0863fd760d652892d5e872a92d5bde4ea55f

Pith citing papers

Observation 752c202b-71bb-45d6-8550-ba2b816a2398 · inbound

Security Threat Modeling for Emerging AI-Agent Protocols: A Comparative Analysis of MCP, A2A, Agora, and ANP cites this paper.

Security Threat Modeling for Emerging AI-Agent Protocols: A Comparative Analysis of MCP, A2A, Agora, and ANP From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers

Reference 63

Resolution
verified exact
arxiv_id, observed 2026-05-20T02:04:54.422307Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-16T05:05:16.370606Z digest=sha256:4ab165e211c39f305b2b6c246ab36adb0bc267addadb3c0785b0e24cabeb3f4a

Observation 5639f668-386b-4f04-a5a0-7b08325695da · inbound

On the dilaton gravity of analogue black holes cites this paper.

On the dilaton gravity of analogue black holes From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers

Reference 6

Resolution
unresolved
no resolver link, observed 2026-07-12T17:06:32.429160Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T17:06:32.429160Z digest=sha256:4f54e661df4e05d38d218a44560cf4a76bb5e0009082bcf06384687d87cb45f9

Observation 4b4a796b-e468-4543-b6db-164ddba2081b · inbound

Red-Teaming Agent Execution Contexts: Open-World Security Evaluation on OpenClaw cites this paper.

Red-Teaming Agent Execution Contexts: Open-World Security Evaluation on OpenClaw From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers

Reference 7

Resolution
metadata mismatch
arxiv_id, observed 2026-05-20T02:04:54.422307Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-13T00:53:56.517406Z digest=sha256:2dbcbb7839e2214c072f2f8900d7c2469b04962c2f5c2751c5124e69d3f910c8

Observation 4c5bf377-26d3-46e0-8e61-90717d3dd3ac · inbound

Behavioral Integrity Verification for AI Agent Skills cites this paper.

Behavioral Integrity Verification for AI Agent Skills From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers

Reference 19

Resolution
metadata mismatch
arxiv_id, observed 2026-05-20T02:04:54.422307Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-05-13T05:54:34.922851Z digest=sha256:7596da7427e7ee8eb0c32f666725c8c7a330512f55110e67d2fa08a7ef05286a

Observation d62ceabc-b69f-4b78-91d6-66fb54856e84 · inbound

When Safe Skills Collide: Measuring Compositional Risk in Agent Skill Ecosystems cites this paper.

When Safe Skills Collide: Measuring Compositional Risk in Agent Skill Ecosystems From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers

Reference 8

Resolution
metadata mismatch
local_arxiv, observed 2026-06-28T19:52:36.039055Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=pdf_text observed=2026-06-28T18:45:33.322389Z digest=sha256:4a3a72da3ba3970ca232f9f842596354956e29d827b43ad91de4aa3540c398a4

Observation 5f52ee4b-68c4-4a30-86b3-b9eaf2d97f1a · inbound

WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents cites this paper.

WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers

Reference 28

Resolution
metadata mismatch
local_arxiv, observed 2026-07-02T14:37:03.247134Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.

source=arxiv_source observed=2026-06-28T00:25:05.443939Z digest=sha256:fcfec097a40fb6ab72a176032a2899ae7c532c750d148205444fe45e18b2f572