ContractGuard: Auditing Semantic Contracts of MCP Tools for Security Violations
Hengkai Ye, Zhechang Zhang, Ruibo Lu, Jinyuan Jia, Hong Hu
Abstract
Model Context Protocol (MCP) is rapidly emerging as a standard interface for connecting large language model (LLM) applications to external tools. An MCP tool exposes two semantic views of the same functionality: a developer-provided description that guides the LLM's tool selection, and an implementation that determines the actual runtime behavior. Security issues arise when these two views diverge, leading to instruction injection, misleading descriptions, malicious code, or unsafe implementations. Existing defenses analyze descriptions or implementations largely in isolation, and thus, fail to address this broader threat space in a unified manner.
We present ContractGuard, the first security-oriented framework for bidirectional semantic contract auditing of MCP tools. Our observation is that diverse MCP threats can be unified as violations of a semantic contract between a tool's description and its implementation. ContractGuard combines reachability-aware static analysis with LLM-based cross-view reasoning for auditing. It extracts a tool-specific code slice, generates a code-grounded description, compares it against the developer-provided one, and validates and classifies detected inconsistencies. We evaluate our method on 3,586 MCP tools from 1,000 real-world MCP servers and 5,661 benchmark cases. Our tool uncovers 116 security issues in the wild, including 21 misleading descriptions, 29 instances of potentially malicious code, and 66 unsafe implementations. It achieves 96.0% true positive rate on malicious-code benchmarks, and more than 92.8% true positive rate on description-attack benchmarks. Results show that contract auditing can effectively identify securityrelevant description-implementation mismatches in MCP tools.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext eca78c77-9cbc-4d2e-9ee7-683f2c88d7d0Builds on24
- Tree of Attacks: Jailbreaking Black-Box LLMs AutomaticallyAnay Mehrotra, Manolis Zampetakis, Paul Kassianik, Blaine Nelson et al.NeurIPS 2024 · 835 citations
- Paraphrasing evades detectors of AI-generated text, but retrieval is an effective defenseKalpesh Krishna, Yixiao Song, Marzena Karpinska, John Wieting et al.NeurIPS 2023 · 657 citations
- Formalizing and Benchmarking Prompt Injection Attacks and DefensesYupei Liu, Yuqi Jia, Runpeng Geng, Jinyuan Jia et al.USENIX Security 2024 · 308 citations
- Prompt Injection Attack to Tool Selection in LLM AgentsJiawen Shi, Zenghui Yuan, Guiyao Tie, Pan Zhou et al.NDSS 2026 · 181 citations
- The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against LLM Jailbreaks and Prompt InjectionsMilad Nasr, Nicholas Carlini, Chawin Sitawarin, Sander V. Schulhoff et al.USENIX Security 2026 · 134 citations
Related papers
- AgentBound: Securing Execution Boundaries of AI AgentsChristoph Bühler, Matteo Biagiola, Luca Di Grazia, Guido SalvaneschiFSE 2026 · 1 citation
- MCP Security Bench (MSB): Benchmarking Attacks Against Model Context Protocol in LLM AgentsDongsen Zhang, Zekun Li, Xu Luo, Xuannan Liu et al.ICLR 2026 · 47 citations
- MCP-SafetyBench: A Benchmark for Safety Evaluation of Large Language Models with Real-World MCP ServersXuanjun Zong, Zhiqi Shen, Lei Wang, Yunshi Lan et al.ICLR 2026 · 34 citations
- ProtocolGuard: Detecting Protocol Non-compliance Bugs via LLM-guided Static Analysis and Dynamic VerificationXiangpu Song, Longjia Pei, Jianliang Wu, Yingpei Zeng et al.NDSS 2026 · 3 citations
- Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP EcosystemShuli Zhao, Qinsheng Hou, Zihan Zhan, Yanhao Wang et al.S&P 2026 · 20 citations
