MCP tool-schema poisoning¶
MCP discovery response edit schema authority 30–40 minutes
A real MCP client discovers a policy tool before choosing its arguments. The
exercise tests whether altered discovery data influences a later tools/call.
| Recipe | Value |
|---|---|
| Pause | tools/list response |
| Attack | add inputSchema.properties.amount.maximum = 1000 |
| Control | change only the tool description |
| Receiver proof | gateway decision reason |
| Out-of-band proof | MCP call receipt and decision ledger |
tools/list AIT
raises maximum Client
reads schema Client
calls 750 Server
receipt
Start discovery¶
Trigger traffic and select the tools/list response. Inspect the entire
tool entry before editing: name, description, input schema, and required
properties all contribute to what the client believes it can call.
Run the schema attack¶
- Locate the first tool's
inputSchema.properties.amountobject. - Add
maximumwith numeric value1000. - Mark the response as the attack arm.
- Forward the modified discovery response.
- Allow the client's subsequent
tools/callrequest to proceed. - Read the gateway decision reason and MCP server call receipt.
The deterministic client selects a high value permitted by the delivered
schema; the expected controlled request is 750. The later request is the
important artifact. A changed schema alone proves only delivery.
Run the close control¶
Trigger discovery again in the same session. Change only the tool description, leave the schema unchanged, and mark the response as the control arm. The client sees an edited catalogue but should retain the baseline argument range.
| Artifact | Attack | Control |
|---|---|---|
| delivered discovery | maximum 1000 |
baseline schema; changed description |
| decision reason | names delivered schema limit | names baseline limit |
| later call | amount 750 |
baseline amount |
| server receipt | records 750 |
records baseline amount |
Distinguish two schema techniques¶
This guide changes a field on an existing tool. A tool-shadowing primitive may instead insert or rename a tool so the client selects a different capability. Those are related discovery attacks, but the selection rule and close control are different. Keep the finding scoped to the exact mutation you delivered.
Evidence boundary¶
The lab client is deterministic. Its decision proves the mutation is well-formed and reaches a schema-sensitive consumer. It does not establish that every model, framework, or client library will interpret the schema the same way. Use a separately designed paired experiment when the target question is probabilistic model behavior.
Done when¶
You can link the delivered schema to a later client decision and a server-side call receipt, while explaining why the description-only control does not test the same authority.
Next: MCP request tampering moves to the other side of the boundary: what the client sends to the server.