📄 Sciences Methods and Technologies
International Journal (SciMeTech)

Volume 2 · Issue 2 · 2026
ISSN: 3085-5284
Securing the Model Context Protocol: A Systematic Analysis of Attack Surfaces and Defense Gaps
Saad Mansouri, Anas Abouelkalam, Wissam Abbass
Pages 158–169 · Research Laboratory in Sustainable and Intelligent Technologies (LaRTID), Cadi Ayyad University, Marrakech, Morocco
Abstract
The emergence of agentic AI has reshaped the trust architecture of modern AI-based applications dramatically by allowing large language models to work with external tools, services, and datasets directly. In this new environment, the Model Context Protocol (MCP) becomes the cornerstone, offering a well-defined structure communication protocol. Within a year after the protocol's public release, the number of public MCP servers exceeded 22,000, and many major platforms, such as Claude Code, and Gemini CLI adopted it as a key integration interface. While this fast adoption reflects the advantages of using MCP, it also demonstrates an inherent contradiction in the basic assumptions behind the creation of the protocol, namely, its lack of security considerations. The initial specification did not include a set of standard security measures that would be needed to mitigate emerging attacks through the use of the protocol itself. As a result, MCP leaves room for numerous new threats based on the mediation of this protocol. As such, securing MCP should go beyond the simple prevention and include advanced threats arising due to security gaps within the protocol itself. In this paper, we present a systematic evaluation of MCP security by synthesizing recent research into a unified taxonomy of six attack families and twenty-three attack vectors. We further review empirical findings on success rates, vulnerability, safety-utility trade-offs, followed by an assessment of the effectiveness of current countermeasures based on a coverage matrix.
Keywords: Model Context Protocol, Agentic AI Security, LLM Vulnerabilities, Supply Chain Security, MCP Attacks

References

  1. Anthropic. 2024. Introducing the Model Context Protocol. https://www.anthropic.com/news/model-context-protocol
  2. Glama, (2026, April). Open-source MCP servers registry. https://glama.ai/mcp/servers
  3. Hou, X., Zhao, Y., Wang, S., & Wang, H. (2025). Model context protocol (MCP): Landscape, security threats, and future research directions. ACM Transactions on Software Engineering and Methodology.
  4. Wang, Z., Zhang, R., Liu, Y., Fan, W., Jiang, W., Zhao, Q., & Xu, G. (2026, March). MPMA: Preference manipulation attack against model context protocol. In Proceedings of the AAAI Conference on Artificial Intelligence (Vol. 40, No. 42, pp. 35838-35846).
  5. Zhao, S., Hou, Q., Zhan, Z., Wang, Y., Xie, Y., Guo, Y., & Xue, Z. (2025). Mind your server: A systematic study of parasitic toolchain attacks on the MCP ecosystem. arXiv preprint arXiv:2509.06572.
  6. Yang, Y., Gao, C., Wu, D., Chen, Y., Li, Y., & Wang, S. (2025). MCPSecBench: A systematic security benchmark and playground for testing Model Context Protocols. arXiv preprint arXiv:2508.13220.
  7. Radosevich, B., & Halloran, J. (2025). MCP safety audit: LLMs with the model context protocol allow major security exploits. arXiv preprint arXiv:2504.03767.
  8. Song, H., Shen, Y., Luo, W., Guo, L., Chen, T., Wang, J., & Chen, J. (2025). Beyond the protocol: Unveiling attack vectors in the model context protocol ecosystem. arXiv preprint arXiv:2506.02040.
  9. Wang, Z., Gao, Y., Wang, Y., Liu, S., Sun, H., Cheng, H., & Li, X. (2026, March). MCPTox: A Benchmark for Tool Poisoning on Real-World MCP Servers. In Proceedings of the AAAI Conference on Artificial Intelligence (Vol. 40, No. 42, pp. 35811-35819).
  10. Guo, Y., Liu, P., Ma, W., Deng, Z., Zhu, X., Di, P., & Wen, S. (2025). Systematic analysis of MCP security. arXiv preprint arXiv:2508.12538.
  11. Zhao, W., Liu, J., Ruan, B., Li, S., & Liang, Z. (2025). When MCP servers attack: Taxonomy, feasibility, and mitigation. arXiv preprint arXiv:2509.24272.
  12. Croce, N., & South, T. (2025). Trivial Trojans: How Minimal MCP Servers Enable Cross-Tool Exfiltration of Sensitive Data. arXiv preprint arXiv:2507.19880.
  13. Hasan, M. M., Li, H., Fallahzadeh, E., Rajbahadur, G. K., Adams, B., & Hassan, A. E. (2025). Model context protocol (MCP) at first glance: Studying the security and maintainability of MCP servers. arXiv preprint arXiv:2506.13538.
  14. Narajala, V. S., & Habler, I. (2026, February). Enterprise-grade security for the model context protocol (MCP): Frameworks and mitigation strategies. In 2026 IEEE 5th International Conference on AI in Cybersecurity (ICAIC) (pp. 1-8). IEEE.
  15. Xing, W., Qi, Z., Qin, Y., Li, Y., Chang, C., Yu, J., & Han, M. (2025). MCP-Guard: A Multi-Stage Defense-in-Depth Framework for Securing Model Context Protocol in Agentic AI. arXiv preprint arXiv:2508.10991.
  16. Kumar, S., Girdhar, A., Patil, R., & Tripathi, D. (2025). MCP guardian: A security-first layer for safeguarding mcp-based AI system. arXiv preprint arXiv:2504.12757.
  17. Jing, H., Li, H., Hu, W., Hu, Q., Heli, X., Chu, T., & Song, Y. (2025, November). MCP: Protecting MCP safety via model contextual integrity protocol. In Proceedings of the 2025 Conference on Empirical Methods in Natural Language Processing (pp. 1177-1194).
  18. Zhou, Z., Zhang, Y., Cai, H., Aloqaily, M., Bouachir, O., Pang, L., & Wen, Q. (2026). MCPShield: A security cognition layer for adaptive trust calibration in Model Context Protocol agents. arXiv preprint arXiv:2602.14281.
  19. Hou, X., Wang, S., Zhang, Y., Xue, Z., Zhao, Y., Fu, C., & Wang, H. (2026). SMCP: Secure Model Context Protocol. arXiv preprint arXiv:2602.01129.
  20. Zhang, D., Li, Z., Luo, X., Liu, X., Li, P., & Xu, W. (2025). MCP Security Bench (MSB): Benchmarking Attacks Against Model Context Protocol in LLM Agents. arXiv preprint arXiv:2510.15994.
  21. Zong, X., Shen, Z., Wang, L., Lan, Y., & Yang, C. (2025). MCP-SafetyBench: A Benchmark for Safety Evaluation of Large Language Models with Real-World MCP Servers. arXiv preprint arXiv:2512.15163.
  22. Rostamzadeh, M., Narula, S., Birhan, N., Ghasemigol, M., & Takabi, D. (2026). MCP-DPT: A Defense-Placement Taxonomy and Coverage Analysis for Model Context Protocol Security. arXiv preprint arXiv:2604.07551.
  23. Huang, C., Huang, X., Tran, N. P., & Fard, A. M. (2026). Model Context Protocol Threat Modeling and Analyzing Vulnerabilities to Prompt Injection with Tool Poisoning. arXiv preprint arXiv:2603.22489.
  24. Tan, Z., Hao, R., Singer, J., Tang, Y., & Anagnostopoulos, C. (2026). MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools. arXiv preprint arXiv:2601.01241.
  25. Wang, B., Liu, Z., Yu, H., Yang, A., Huang, Y., Guo, J., & Wu, H. (2025). Mcpguard: Automatically detecting vulnerabilities in MCP servers. arXiv preprint arXiv:2510.23673.
  26. Li, Q., & Xie, Y. (2025). From glue-code to protocols: A critical analysis of a2a and MCP integration for scalable agent systems. arXiv preprint arXiv:2505.03864.
  27. Beurer-Kellner, L., & Fischer, M. (2025). Mep security notification: Tool poisoning attacks. Invariant Labs Blog. https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks
  28. Google Cloud. (2026, April 21). Agent Registry Documentation: Overview. Google Cloud Documentation. https://docs.cloud.google.com/agent-registry/overview