Skip to content

No-Box Vulnerability Analysis: Description-only Detection of Indirect Prompt Injection Vulnerabilities in MCP Servers

Sep 2026 · 0 citations · 58 references
Computer Science

TL;DR

This work proposes a new paradigm of no-box vulnerability analysis in which neither access nor runtime interaction is available, and only functionality metadata is available, and introduces no-box vulnerability analysis as a new analysis paradigm and demonstrates its practical feasibility in realistic systems.

Abstract

Conventional vulnerability analysis relies on either system access or dynamic interaction, all of which may be unavailable to third-party analysts auditing closed-source, remotely hosted, critical in situ systems, or commercially gated software. Therefore, we propose a new paradigm of no-box vulnerability analysis in which neither access nor runtime interaction is available, and only functionality metadata is available. Such metadata defines the intended behavior of the system, including its inputs, outputs, and side effects, while constraining the space of implementations consistent with that behavior. We propose hypothesizing about vulnerabilities that exist across all possible implementations of a given system metadata, without observing or interacting with the target system. An analyst can later validate these hypotheses when additional access is available. We showcase the feasibility of no-box vulnerability analysis through implementing a prototype called MCPSEC, which audits Model Context Protocol (MCP) servers for indirect prompt injection vulnerabilities using only the tool metadata exposed at server registration time. We evaluate MCPSEC on 20 widely deployed MCP servers comprising 177 tools, among which human evaluators confirm 95 vulnerable tools. MCPSEC identified 143 tools as vulnerable, and for each vulnerable tool, it produced a hypothesized vulnerability along with exploitation technique. Using metadata alone, MCPSEC predicted 94 (98.9% recall) real verified vulnerabilities, compared against an LLM baseline with 80 (84.2% recall). Overall, our results introduce no-box vulnerability analysis as a new analysis paradigm and demonstrate its practical feasibility in realistic systems.

View source

Similar papers

Review Open access Aug 2026

Defensive Reverse Engineering of LLM Applications: A Black-Box Framework for Security Risk Scoring and Mitigation

D-RELLM is presented, a defensive reverse-engineering framework for black-box security assessment of deployed LLM applications that treats the deployed application as a socio-technical system whose risk depends on instruction hierarchy, retrieval trust, authorization, tool agency, output handling, monitoring, and opera...

Bhavesh B. Prajapati, Bhavya Shah · 0 citations

Defensive Capability Analysis for JavaScript Libraries

A defensive capability analysis for JavaScript libraries that soundly reports every exercised capability for code executed under a lightweight protected runtime, complementing the static analysis with a lightweight runtime enforcement mechanism that blocks those patterns.

Unknown authors · 1 citation

Defensive Capability Analysis for JavaScript Libraries

A defensive capability analysis for JavaScript libraries that soundly reports every exercised capability for code executed under a lightweight protected runtime, complementing the static analysis with a lightweight runtime enforcement mechanism that blocks those patterns.

Unknown authors · 1 citation
#artificial intelligence Preprint Sep 2026

Vulnerability Localization Benchmark: Measuring Agentic Security Analysis at Repository Scale

VLoc Benchmark results establish vulnerability localization as a distinct repository-scale capability and provide a setting for studying both how security agents search for vulnerable code and when they should refrain from reporting it.

Aman Priyanshu, Supriti Vijay, Kimia Majd et al. · 0 citations
#artificial intelligence Preprint Sep 2026

Beyond Static Guarantees: Measuring the Static-Pass Dynamic-Fail Gap in Security-Sensitive and LLM-Generated Python Code

Advances in large language models (LLMs) fuel the quest for scalable methods to assess the security of generated and security-sensitive software. Static analysis is widely adopted as a scalable, reproducible, and inexpensive security gate, but cannot directly observe runtime exploit behaviour. Vulnerabilities dependent...

Jessica Pourleyli, Maitreyee Das Urmi, Glaucia Melo · 0 citations
Open access Aug 2026

Response-Level Identification of Cloud API Misconfigurations Using Large Language Models †

This study investigates the use of Large Language Models to detect security misconfigurations directly from cloud API response data and evaluates each model’s capability to accurately determine the number of misconfigurations and generate clear, actionable security explanations.

A. Krishna, Farzana Zahid · 0 citations

Related blog posts

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.