Skip to content

MCP tool-result alteration

MCP response structured content client decision 25–35 minutes

A gateway consumes a structured policy result from a real MCP server. The exercise tests whether changing returned tool data changes the downstream decision made by the client.

Recipe Value
Pause tools/call response
Attack structured risk from low to high
Control change only descriptive response text
Receiver proof gateway decision state
Out-of-band proof controlled effect ledger
Gateway
tool call
MCP server
risk low
AIT
risk high
Gateway
decides
Effect
ledger

Start the HTTP workflow

ait lab start --exercise mcp-tool-result

Trigger the exercise. The traffic timeline shows a tools/call request and its correlated response. Pause on the response. Editing the request would test server argument handling instead.

Run the structured-data attack

  1. Open the tools/call response.
  2. Confirm /result/structuredContent/risk is low.
  3. Set the arm to attack and change it to high.
  4. Inspect the diff and forward the modified response.
  5. Read gateway decision state.
  6. Read the effect ledger.

If the client consumes the structured result, its decision state should name the delivered risk. The ledger records the controlled action that followed.

Run the close control

Trigger another call in the same session. Change descriptive text in the response while leaving structuredContent.risk at low. Mark it as the control arm and forward it.

The control is visible to the same client and travels in the same response. It separates structured authority from a generic response mutation.

Repeat over stdio

ait lab start --exercise mcp-tool-result --mcp-transport stdio

The wrapped stdio workflow uses the same client/server semantics through real pipes rather than Streamable HTTP. Record the transport with the evidence; a successful HTTP run does not prove wrapper behavior.

Read the evidence

Evidence Strongest supported statement
edited response only AIT formed and delivered a mutation
gateway decision shows high the controlled client processed the mutation
effect ledger changes only in attack behavior changed under the structured-field edit
same result over HTTP and stdio the controlled result is not confined to one tested transport

An external oracle on an authorized target may be a transaction sandbox, policy decision log, or downstream service receipt. The lab's ledger proves only its own controlled action.

Done when

You can distinguish request from response, structured content from descriptive text, client decision from external effect, and HTTP from stdio evidence.

Next: MCP tool-schema poisoning moves earlier in the lifecycle, before the client chooses a tool argument.