首次测量MCP生态中API使用风险,揭示权限管理缺失隐患
We Urgently Need Privilege Management in MCP: A Measurement of API Usage in MCP Ecosystems
- 构建静态分析框架,扫描2562个MCP应用
- 1438个服务器受网络接口影响,1237个受系统资源调用影响
- 开发工具类插件最危险,建议动态权限与信任评估
模型上下文协议(MCP)已成为连接大语言模型与外部工具的主流机制。尽管其提供丰富集成能力,但也显著扩大了攻击面:任意插件可继承广泛系统权限且缺乏隔离与监督。本文首次开展大规模实证分析,开发自动化静态分析框架,系统考察2562个真实MCP应用,覆盖23种功能类别。结果显示,网络与系统资源接口使用最为普遍,分别影响1438和1237个服务器;文件与内存资源调用较少但仍具风险。发现开发者工具与API开发类插件最为频繁调用接口,而低关注度插件常包含高危操作。通过案例研究,证实权限隔离不足可导致权限提升、信息误导与数据篡改。基于此,提出MCP资源访问分类体系,量化安全相关接口使用情况,并指出动态权限模型与自动化信任评估等关键挑战。
原文摘要 · Abstract (English)
The Model Context Protocol (MCP) has emerged as a widely adopted mechanism for connecting large language models to external tools and resources. While MCP promises seamless extensibility and rich integrations, it also introduces a substantially expanded attack surface: any plugin can inherit broad system privileges with minimal isolation or oversight. In this work, we conduct the first large-scale empirical analysis of MCP security risks. We develop an automated static analysis framework and systematically examine 2,562 real-world MCP applications spanning 23 functional categories. Our measurements reveal that network and system resource APIs dominate usage patterns, affecting 1,438 and 1,237 servers respectively, while file and memory resources are less frequent but still significant. We find that Developer Tools and API Development plugins are the most API-intensive, and that less popular plugins often contain disproportionately high-risk operations. Through concrete case studies, we demonstrate how insufficient privilege separation enables privilege escalation, misinformation propagation, and data tampering. Based on these findings, we propose a detailed taxonomy of MCP resource access, quantify security-relevant API usage, and identify open challenges for building safer MCP ecosystems, including dynamic permission models and automated trust assessment.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。