MCP tool-result alteration¶
MCP response structured content client decision 25–35 minutes
A gateway consumes a structured policy result from a real MCP server. The exercise tests whether changing returned tool data changes the downstream decision made by the client.
| Recipe | Value |
|---|---|
| Pause | tools/call response |
| Attack | structured risk from low to high |
| Control | change only descriptive response text |
| Receiver proof | gateway decision state |
| Out-of-band proof | controlled effect ledger |
tool call MCP server
risk low AIT
risk high Gateway
decides Effect
ledger
Start the HTTP workflow¶
Trigger the exercise. The traffic timeline shows a tools/call request and its
correlated response. Pause on the response. Editing the request would test
server argument handling instead.
Run the structured-data attack¶
- Open the
tools/callresponse. - Confirm
/result/structuredContent/riskislow. - Set the arm to attack and change it to
high. - Inspect the diff and forward the modified response.
- Read gateway decision state.
- Read the effect ledger.
If the client consumes the structured result, its decision state should name the delivered risk. The ledger records the controlled action that followed.
Run the close control¶
Trigger another call in the same session. Change descriptive text in the
response while leaving structuredContent.risk at low. Mark it as the control
arm and forward it.
The control is visible to the same client and travels in the same response. It separates structured authority from a generic response mutation.
Repeat over stdio¶
The wrapped stdio workflow uses the same client/server semantics through real pipes rather than Streamable HTTP. Record the transport with the evidence; a successful HTTP run does not prove wrapper behavior.
Read the evidence¶
| Evidence | Strongest supported statement |
|---|---|
| edited response only | AIT formed and delivered a mutation |
gateway decision shows high |
the controlled client processed the mutation |
| effect ledger changes only in attack | behavior changed under the structured-field edit |
| same result over HTTP and stdio | the controlled result is not confined to one tested transport |
An external oracle on an authorized target may be a transaction sandbox, policy decision log, or downstream service receipt. The lab's ledger proves only its own controlled action.
Done when¶
You can distinguish request from response, structured content from descriptive text, client decision from external effect, and HTTP from stdio evidence.
Next: MCP tool-schema poisoning moves earlier in the lifecycle, before the client chooses a tool argument.