There are 5 attacks in the mcp-exploitation category. Each shows its technique id, mode, standards mapping, description, and the exact command to run it (swap the provider and target as needed).
critical
mcp-command-injection · tool-use · OWASP: LLM03, LLM01 · MITRE: AML.T0110.001, AML.T0050Shell metacharacters injected into MCP tool parameters to execute arbitrary commandsRun it:
critical
mcp-data-exfiltration · tool-use · OWASP: LLM02, LLM03 · MITRE: AML.T0085.001, AML.T0086Agent tricked into embedding sensitive data in URLs or webhooks via MCP tool side channelsRun it:
critical
mcp-tool-poisoning · tool-use · OWASP: LLM02, LLM03 · MITRE: AML.T0110.000, AML.T0011.002Hidden instructions embedded in MCP tool descriptions manipulate agent behaviorRun it:
high
mcp-rug-pull · tool-use · OWASP: LLM03, LLM02 · MITRE: AML.T0109, AML.T0010.005Previously trusted MCP tool changes behavior mid-session to request credentialsRun it:
high
mcp-server-impersonation · tool-use · OWASP: LLM02, LLM03 · MITRE: AML.T0111, AML.T0010.005Malicious MCP server impersonates a trusted service to harvest credentialsRun it: