Glossary · term

MCP Sampling Attacks

An attack vector arising from the sampling feature in MCP, which lets a server initiate queries to the client's model, reversing the typical direction of interaction. A malicious or compromised server can abuse the model in this way to steal resources and API quota, inject persistent instructions that hijack the conversation, or invoke tools (writing files, exfiltration) without the user's consent.

Safety2026Wave 3 · 2025–26Maturity: 4/5

Maturity rationale

Palo Alto Unit 42 security research

References

Author: Społeczność / Anonimowi