arXiv:2602.03580cs.CRcs.AI2026-02被引 8

发现13%的AI工具描述与实际代码不符,可能引发安全漏洞

Don't believe everything you read: Understanding and Measuring MCP Behavior under Misleading Tool Descriptions

  • 通过自动化分析检测10240个MCP服务器的描述与代码一致性
  • 约13%存在严重不一致,可导致未授权操作或资金损失
  • 提醒开发者和平台需加强工具透明度与审计机制

模型上下文协议(MCP)使大语言模型能通过自然语言调用外部工具,构成众多AI代理应用的基础。然而,MCP未强制要求工具文档行为与实际代码执行保持一致,即使MCP服务器常具备高权限。这一差距带来尚未被充分探索的安全风险。我们首次对MCP生态中的描述-代码不一致现象进行了大规模研究,设计并应用自动化静态分析框架于跨36类、共10,240个真实MCP服务器。结果显示,尽管多数服务器高度一致,约13%存在显著不一致,可能导致未记录的特权操作、隐藏状态变更或未经授权的金融行为。不同应用类别、流行度及市场间也存在系统性差异。结果表明,描述-代码不一致是MCP驱动的AI代理中真实且普遍存在的攻击面,亟需未来生态系统建立系统性审计与更强透明性保障。

原文摘要 · Abstract (English)

The Model Context Protocol (MCP) enables large language models to invoke external tools through natural-language descriptions, forming the foundation of many AI agent applications. However, MCP does not enforce consistency between documented tool behavior and actual code execution, even though MCP Servers often run with broad system privileges. This gap introduces a largely unexplored security risk. We study how mismatches between externally presented tool descriptions and underlying implementations systematically shape the mental models and decision-making behavior of intelligent agents. Specifically, we present the first large-scale study of description-code inconsistency in the MCP ecosystem. We design an automated static analysis framework and apply it to 10,240 real-world MCP Servers across 36 categories. Our results show that while most servers are highly consistent, approximately 13% exhibit substantial mismatches that can enable undocumented privileged operations, hidden state mutations, or unauthorized financial actions. We further observe systematic differences across application categories, popularity levels, and MCP marketplaces. Our findings demonstrate that description-code inconsistency is a concrete and prevalent attack surface in MCP-based AI agents, and motivate the need for systematic auditing and stronger transparency guarantees in future agent ecosystems.

AI安全MCP工具审计大模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。