arXiv:2512.08290cs.CRcs.AI2025-12被引 21

剖析MCP生态安全风险,揭示上下文如何被武器化攻击

Systematization of Knowledge: Security and Safety in the Model Context Protocol Ecosystem

  • 构建MCP生态风险分类体系,区分安全威胁与认知安全问题
  • 发现资源、提示、工具三类原语存在可被利用的结构漏洞
  • 适合关注AI代理系统安全的开发者与研究者阅读

模型上下文协议(MCP)已成为连接大语言模型与外部数据及工具的事实标准,相当于智能代理AI的“USB-C接口”。尽管这种上下文与执行解耦解决了互操作性难题,但也催生了全新的威胁环境,使得认知错误(幻觉)与安全漏洞(未经授权操作)之间的界限模糊。本文作为知识体系化(SoK)研究,全面梳理了MCP生态中的风险,区分了对抗性安全威胁(如间接提示注入、工具污染)与认知安全隐患(如分布式工具委派中的对齐失败)。分析了MCP基本组件——资源、提示、工具的结构性弱点,证明‘上下文’可在多智能体环境中被恶意利用以触发未授权操作。同时综述了现有防御技术,涵盖密码学溯源(ETDI)与运行时意图验证,并提出从对话机器人向自主代理操作系统演进的安全路线图。

原文摘要 · Abstract (English)

The Model Context Protocol (MCP) has emerged as the de facto standard for connecting Large Language Models (LLMs) to external data and tools, effectively functioning as the "USB-C for Agentic AI." While this decoupling of context and execution solves critical interoperability challenges, it introduces a profound new threat landscape where the boundary between epistemic errors (hallucinations) and security breaches (unauthorized actions) dissolves. This Systematization of Knowledge (SoK) aims to provide a comprehensive taxonomy of risks in the MCP ecosystem, distinguishing between adversarial security threats (e.g., indirect prompt injection, tool poisoning) and epistemic safety hazards (e.g., alignment failures in distributed tool delegation). We analyze the structural vulnerabilities of MCP primitives, specifically Resources, Prompts, and Tools, and demonstrate how "context" can be weaponized to trigger unauthorized operations in multi-agent environments. Furthermore, we survey state-of-the-art defenses, ranging from cryptographic provenance (ETDI) to runtime intent verification, and conclude with a roadmap for securing the transition from conversational chatbots to autonomous agentic operating systems.

AI安全MCP代理系统风险建模

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。