AI threat catalogueApplication and Integration SecurityProduction
MCP Hijacking (Model Context Protocol)
The Model Context Protocol (MCP) connects AI assistants to external tools and data sources in a standardised way. Attackers hijack MCP servers or manipulate their tool descriptions and thereby control what the AI system sees and does.
Description
MCP servers provide tools to an AI system and describe them in manifests (description files) the system trusts. Attackers strike at several points: they operate or take over an MCP server, distribute initially harmless servers and later ship a malicious update, poison tool descriptions with hidden instructions, or insert themselves into unprotected connections (man-in-the-middle, reading and altering the traffic). The manipulated content reaches the model as seemingly trustworthy context and undermines the trust boundary between application and model. Thousands of freely available MCP servers circulate without consistent security vetting.
Possible impact
Attackers read everything that flows through the assistant, including emails, documents and credentials, trigger commands within the assistant's permissions or silently redirect results. Because everything runs through legitimate tool calls, the attack is hard to notice in operation. The risks include data leakage with GDPR consequences, manipulated work results and loss of control over connected systems.
Example
A team connects a freely available MCP server for sending emails to its AI assistant. After several unremarkable versions, the provider ships an update that forwards every sent email as a blind copy to the attacker.
Recommended mitigations (6)
Every mitigation states its control type, effect, implementation level and the reason for the classification.
Authenticated MCP server connectionsTechnical
- Effect
- Preventive
- Implementation level
- Application, API & agents, Infrastructure
- Reason for the classification
- “Authenticated MCP server connections” is primarily technical: Machine-enforced identity, permission, or scope rules constrain unauthorized access and actions.
Tool manifest signing and verificationTechnical
- Effect
- Preventive, Detective
- Implementation level
- Application, API & agents, Supply chain
- Complementary control type
- Organizational & process-based
- Reason for the classification
- “Tool manifest signing and verification” is primarily technical: Cryptographic or machine-verifiable properties protect confidentiality, integrity, or provenance; complemented by binding workflows.
TLS-protected MCP transportTechnical
- Effect
- Preventive
- Implementation level
- Application, API & agents, Infrastructure
- Reason for the classification
- “TLS-protected MCP transport” is primarily technical: Cryptographic or machine-verifiable properties protect confidentiality, integrity, or provenance.
Allowlist of approved MCP serversTechnical
- Effect
- Preventive
- Implementation level
- Application, API & agents, Organization, Supply chain
- Complementary control type
- Governance & compliance
- Reason for the classification
- “Allowlist of approved MCP servers” is primarily technical: Machine-enforced identity, permission, or scope rules constrain unauthorized access and actions; complemented by rules and oversight.
Runtime integrity checks on tool definitionsTechnical
- Effect
- Preventive, Detective
- Implementation level
- Application, API & agents, Use & operations
- Reason for the classification
- “Runtime integrity checks on tool definitions” is primarily technical: Software or analytical tools systematically produce and evaluate measurements, deviations, or attack indicators.
Audit logging of MCP interactionsTechnical
- Effect
- Detective
- Implementation level
- Application, API & agents, Use & operations
- Complementary control type
- Organizational & process-based
- Reason for the classification
- “Audit logging of MCP interactions” is primarily technical: Software or analytical tools systematically produce and evaluate measurements, deviations, or attack indicators; complemented by binding workflows.
Framework mappings
Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.
Verified references (14)
Every reference states the framework, the exact location and the publishing organisation.
- OWASP LLM Top 10 ASI01:2026 Agent Goal HijackASI01 Agent Goal Hijack, pp. 9–11 of the official PDF OWASP FoundationOriginal
- OWASP LLM Top 10 ASI02:2026 Tool Misuse and ExploitationASI02 Tool Misuse and Exploitation, pp. 12–14 of the official PDF OWASP FoundationOriginal
- OWASP LLM Top 10 ASI04:2026 Agentic Supply Chain VulnerabilitiesASI04 Agentic Supply Chain Vulnerabilities, pp. 18–20 of the official PDF OWASP FoundationOriginal
- OWASP LLM Top 10 LLM01:2025 Prompt InjectionLLM01:2025 Prompt Injection, official category page OWASP FoundationOriginal
- OWASP LLM Top 10 LLM06:2025 Excessive AgencyLLM06:2025 Excessive Agency, official category page OWASP FoundationOriginal
- NIST AI RMF Section 3.5 Security of AgentsSection 3.5, p. 54 National Institute of Standards and Technology (NIST)Original
- NIST AI RMF NISTAML.015 Indirect Prompt InjectionTaxonomy Index, pp. x–xi; Section 3.4, pp. 50–53; Glossary, p. 110 National Institute of Standards and Technology (NIST)Original
- NIST AI RMF NISTAML.039 Compromising connected resourcesTaxonomy Index, p. xi; Section 3.4.3, pp. 52–53 National Institute of Standards and Technology (NIST)Original
- MITRE ATLAS AML.T0048 External HarmsATLAS.yaml technique object with id AML.T0048 (pinned release v5.6.0) MITREOriginal
- MITRE ATLAS AML.T0051 LLM Prompt InjectionATLAS.yaml technique object with id AML.T0051 (pinned release v5.6.0) MITREOriginal
- MITRE ATLAS AML.T0053 AI Agent Tool InvocationATLAS.yaml technique object with id AML.T0053 (pinned release v5.6.0) MITREOriginal
- EU AI Act Article 14(4)(d) Human oversightArticle 14(4)(d); for automation bias, Article 14(4)(b) European Union (EUR-Lex)Original
- EU AI Act Article 9(1), 9(2)(a), 9(2)(d) Risk management systemArticle 9(1), 9(2)(a), 9(2)(d), read with Article 9(3) European Union (EUR-Lex)Original
- BSI R28 Indirect Prompt Injections (Text)Kap. 4, R28, p. 33 Bundesamt für Sicherheit in der Informationstechnik (BSI)Original
Terms on this page
Glossary terms that occur in this entry. Every link leads to the full explanation.
- MCP (Model Context Protocol) Open standard through which a model connects to tools and data sources.
Related threats
More entries from the topic group Application and Integration Security.
Assess this threat in your own system
The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.
Cite this entry
For reports, policies or internal documents; the link leads directly to this entry.
“MCP Hijacking (Model Context Protocol)”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026. https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/mcp-hijacking/