{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:2DETMO2NT7YBYKH3A22AGAV63O","short_pith_number":"pith:2DETMO2N","schema_version":"1.0","canonical_sha256":"d0c9363b4d9ff01c28fb06b40302bedbbc3507555d9fbf0e6db45dae947c1afd","source":{"kind":"arxiv","id":"2504.03767","version":2},"attestation_state":"computed","paper":{"title":"MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.LG"],"primary_cat":"cs.CR","authors_text":"Brandon Radosevich, John Halloran","submitted_at":"2025-04-02T21:46:02Z","abstract_excerpt":"To reduce development overhead and enable seamless integration between potential components comprising any given generative AI application, the Model Context Protocol (MCP) (Anthropic, 2024) has recently been released and subsequently widely adopted. The MCP is an open protocol that standardizes API calls to large language models (LLMs), data sources, and agentic tools. By connecting multiple MCP servers, each defined with a set of tools, resources, and prompts, users are able to define automated workflows fully driven by LLMs. However, we show that the current MCP design carries a wide range "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2504.03767","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-04-02T21:46:02Z","cross_cats_sorted":["cs.AI","cs.LG"],"title_canon_sha256":"f15e0685a81598cb6bd14cade6b59bf96d919e380f043804616c0f1a8e0ac9f1","abstract_canon_sha256":"c618deb484c6e7e7dfc4d70ed122b9ad5602865e38e87088a370a396c2869165"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:47:37.924205Z","signature_b64":"jBcH2GZ6Adxe5lE+dmDiTeDATl1y1lJAYzDQ61X1zoX3Te5Xzj0gErUTLPBq/paakPRu5Aelnw5y0R//Il1SCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"d0c9363b4d9ff01c28fb06b40302bedbbc3507555d9fbf0e6db45dae947c1afd","last_reissued_at":"2026-07-05T10:47:37.923740Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:47:37.923740Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.LG"],"primary_cat":"cs.CR","authors_text":"Brandon Radosevich, John Halloran","submitted_at":"2025-04-02T21:46:02Z","abstract_excerpt":"To reduce development overhead and enable seamless integration between potential components comprising any given generative AI application, the Model Context Protocol (MCP) (Anthropic, 2024) has recently been released and subsequently widely adopted. The MCP is an open protocol that standardizes API calls to large language models (LLMs), data sources, and agentic tools. By connecting multiple MCP servers, each defined with a set of tools, resources, and prompts, users are able to define automated workflows fully driven by LLMs. However, we show that the current MCP design carries a wide range "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2504.03767","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2504.03767/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2504.03767","created_at":"2026-07-05T10:47:37.923795+00:00"},{"alias_kind":"arxiv_version","alias_value":"2504.03767v2","created_at":"2026-07-05T10:47:37.923795+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2504.03767","created_at":"2026-07-05T10:47:37.923795+00:00"},{"alias_kind":"pith_short_12","alias_value":"2DETMO2NT7YB","created_at":"2026-07-05T10:47:37.923795+00:00"},{"alias_kind":"pith_short_16","alias_value":"2DETMO2NT7YBYKH3","created_at":"2026-07-05T10:47:37.923795+00:00"},{"alias_kind":"pith_short_8","alias_value":"2DETMO2N","created_at":"2026-07-05T10:47:37.923795+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":31,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2607.08288","citing_title":"From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure","ref_index":18,"is_internal_anchor":true},{"citing_arxiv_id":"2606.27027","citing_title":"ShareLock: A Stealthy Multi-Tool Threshold Poisoning Attack Against MCP","ref_index":23,"is_internal_anchor":false},{"citing_arxiv_id":"2606.21338","citing_title":"\"What Happens Locally, Leaks Globally\": Detecting Privacy Leakage Risks in MCP Servers","ref_index":25,"is_internal_anchor":false},{"citing_arxiv_id":"2606.03024","citing_title":"SkillGuard: A Permission-Centric Framework for Agent Skill Security","ref_index":25,"is_internal_anchor":false},{"citing_arxiv_id":"2606.01494","citing_title":"ClawHub Security Signals: When VirusTotal, Static Analysis, and SkillSpector Disagree","ref_index":42,"is_internal_anchor":false},{"citing_arxiv_id":"2606.30755","citing_title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","ref_index":25,"is_internal_anchor":false},{"citing_arxiv_id":"2606.31227","citing_title":"Securing the AI Agent: A Unified Framework for Multi-Layer Agent Red Teaming","ref_index":33,"is_internal_anchor":false},{"citing_arxiv_id":"2605.28617","citing_title":"LACUNA: Safe Agents as Recursive Program Holes","ref_index":2,"is_internal_anchor":false},{"citing_arxiv_id":"2605.28148","citing_title":"DeltaMCP: Incremental Regeneration via Spec-Aware Transformation for MCP servers","ref_index":12,"is_internal_anchor":false},{"citing_arxiv_id":"2512.06556","citing_title":"Semantic Attacks on Tool-Augmented LLMs: Securing the Model Context Protocol Against Descriptor-Level Manipulation","ref_index":33,"is_internal_anchor":false},{"citing_arxiv_id":"2605.22333","citing_title":"A First Measurement Study on Authentication Security in Real-World Remote MCP Servers","ref_index":8,"is_internal_anchor":false},{"citing_arxiv_id":"2604.01905","citing_title":"From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers","ref_index":60,"is_internal_anchor":false},{"citing_arxiv_id":"2605.21392","citing_title":"VIPER-MCP: Detecting and Exploiting Taint-Style Vulnerabilities in Model Context Protocol Servers","ref_index":13,"is_internal_anchor":false},{"citing_arxiv_id":"2605.17830","citing_title":"Remembering More, Risking More: Longitudinal Safety Risks in Memory-Equipped LLM Agents","ref_index":99,"is_internal_anchor":false},{"citing_arxiv_id":"2506.13538","citing_title":"Model Context Protocol (MCP) at First Glance: Studying the Security and Maintainability of MCP Servers","ref_index":108,"is_internal_anchor":false},{"citing_arxiv_id":"2509.06572","citing_title":"Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP Ecosystem","ref_index":43,"is_internal_anchor":false},{"citing_arxiv_id":"2510.14133","citing_title":"Formalizing the Safety, Security, and Functional Properties of Agentic AI Systems","ref_index":48,"is_internal_anchor":false},{"citing_arxiv_id":"2510.21236","citing_title":"AgentBound: Securing Execution Boundaries of AI Agents","ref_index":38,"is_internal_anchor":false},{"citing_arxiv_id":"2602.11327","citing_title":"Security Threat Modeling for Emerging AI-Agent Protocols: A Comparative Analysis of MCP, A2A, Agora, and ANP","ref_index":20,"is_internal_anchor":false},{"citing_arxiv_id":"2603.00991","citing_title":"Tracking Capabilities for Safer Agents","ref_index":63,"is_internal_anchor":false},{"citing_arxiv_id":"2604.03070","citing_title":"How Your Credentials Are Leaked by LLM Agent Skills: An Empirical Study","ref_index":47,"is_internal_anchor":false},{"citing_arxiv_id":"2503.23278","citing_title":"Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions","ref_index":56,"is_internal_anchor":false},{"citing_arxiv_id":"2605.11217","citing_title":"Leveraging RAG for Training-Free Alignment of LLMs","ref_index":51,"is_internal_anchor":false},{"citing_arxiv_id":"2604.11790","citing_title":"ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection","ref_index":31,"is_internal_anchor":false},{"citing_arxiv_id":"2605.09889","citing_title":"Skill Description Deception Attack against Task Routing in Internet of Agents","ref_index":9,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/2DETMO2NT7YBYKH3A22AGAV63O","json":"https://pith.science/pith/2DETMO2NT7YBYKH3A22AGAV63O.json","graph_json":"https://pith.science/api/pith-number/2DETMO2NT7YBYKH3A22AGAV63O/graph.json","events_json":"https://pith.science/api/pith-number/2DETMO2NT7YBYKH3A22AGAV63O/events.json","paper":"https://pith.science/paper/2DETMO2N"},"agent_actions":{"view_html":"https://pith.science/pith/2DETMO2NT7YBYKH3A22AGAV63O","download_json":"https://pith.science/pith/2DETMO2NT7YBYKH3A22AGAV63O.json","view_paper":"https://pith.science/paper/2DETMO2N","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2504.03767&json=true","fetch_graph":"https://pith.science/api/pith-number/2DETMO2NT7YBYKH3A22AGAV63O/graph.json","fetch_events":"https://pith.science/api/pith-number/2DETMO2NT7YBYKH3A22AGAV63O/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/2DETMO2NT7YBYKH3A22AGAV63O/action/timestamp_anchor","attest_storage":"https://pith.science/pith/2DETMO2NT7YBYKH3A22AGAV63O/action/storage_attestation","attest_author":"https://pith.science/pith/2DETMO2NT7YBYKH3A22AGAV63O/action/author_attestation","sign_citation":"https://pith.science/pith/2DETMO2NT7YBYKH3A22AGAV63O/action/citation_signature","submit_replication":"https://pith.science/pith/2DETMO2NT7YBYKH3A22AGAV63O/action/replication_record"}},"created_at":"2026-07-05T10:47:37.923795+00:00","updated_at":"2026-07-05T10:47:37.923795+00:00"}