Skip to content

MCP tool-schema poisoning

MCP discovery response edit schema authority 30–40 minutes

A real MCP client discovers a policy tool before choosing its arguments. The exercise tests whether altered discovery data influences a later tools/call.

Recipe Value
Pause tools/list response
Attack add inputSchema.properties.amount.maximum = 1000
Control change only the tool description
Receiver proof gateway decision reason
Out-of-band proof MCP call receipt and decision ledger
MCP server
tools/list
AIT
raises maximum
Client
reads schema
Client
calls 750
Server
receipt

Start discovery

ait lab start --exercise mcp-tool-schema

Trigger traffic and select the tools/list response. Inspect the entire tool entry before editing: name, description, input schema, and required properties all contribute to what the client believes it can call.

Run the schema attack

  1. Locate the first tool's inputSchema.properties.amount object.
  2. Add maximum with numeric value 1000.
  3. Mark the response as the attack arm.
  4. Forward the modified discovery response.
  5. Allow the client's subsequent tools/call request to proceed.
  6. Read the gateway decision reason and MCP server call receipt.

The deterministic client selects a high value permitted by the delivered schema; the expected controlled request is 750. The later request is the important artifact. A changed schema alone proves only delivery.

Run the close control

Trigger discovery again in the same session. Change only the tool description, leave the schema unchanged, and mark the response as the control arm. The client sees an edited catalogue but should retain the baseline argument range.

Artifact Attack Control
delivered discovery maximum 1000 baseline schema; changed description
decision reason names delivered schema limit names baseline limit
later call amount 750 baseline amount
server receipt records 750 records baseline amount

Distinguish two schema techniques

This guide changes a field on an existing tool. A tool-shadowing primitive may instead insert or rename a tool so the client selects a different capability. Those are related discovery attacks, but the selection rule and close control are different. Keep the finding scoped to the exact mutation you delivered.

Evidence boundary

The lab client is deterministic. Its decision proves the mutation is well-formed and reaches a schema-sensitive consumer. It does not establish that every model, framework, or client library will interpret the schema the same way. Use a separately designed paired experiment when the target question is probabilistic model behavior.

Done when

You can link the delivered schema to a later client decision and a server-side call receipt, while explaining why the description-only control does not test the same authority.

Next: MCP request tampering moves to the other side of the boundary: what the client sends to the server.