Skip to content

Hardening: Tool-definition authorization surfaces and parameter bounds on reference servers #4958

Description

@zariffromlatif

Hello maintainers,

I run LIFE FORGE, an MIT-licensed open-source security scanner for MCP tool definitions (github.com/zariffromlatif/life-forge). I recently scanned the most-installed servers in the ecosystem and want to share the findings on your reference implementations directly, before publishing summaries elsewhere.

What the scanner flagged on server-filesystem (probed live over stdio, definitions read off the wire):

  • write_file performs a state-mutating operation with no confirmation, approval-token, or dry-run argument in its schema. Under indirect prompt injection - an attacker-controlled document instructing the agent to write a file - the only gate is the model's own judgment.
  • All 14 tools declare string parameters without maxLength/pattern bounds, which admits arbitrary-length payloads into the agent's context.

On server-git: all 12 tools declare unbounded string parameters. No destructive-capability flags - the concern here is parameter bounding only.

These are design-level observations about the definitions, not claims of an exploitable vulnerability, and I recognize reference servers trade hardening for pedagogical clarity. But they are also the templates people copy, and the fix pattern (a confirm: true argument enforced server-side; maxLength on path/string parameters) costs a few lines per tool and would set the ecosystem standard.

Full report: results/MCP_ECOSYSTEM_SCAN.md in the repository above (per-server JSON evidence included; the ruleset is versioned and findings reproduce deterministically). If you believe any finding is wrong, I will re-run and publish a correction. I have not posted about your servers individually and will hold individual publicity until you have had a reasonable window.

Zarif Latif
Founder, Railo & LIFE FORGE
zarif.latif.biz@gmail.com
https://github.com/zariffromlatif/life-forge

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions