ContractGuard: Auditing Semantic Contracts of MCP Tools for Security Violations
Hengkai Ye, Zhechang Zhang, Ruibo Lu, Jinyuan Jia, Hong Hu
摘要
Model Context Protocol (MCP) is rapidly emerging as a standard interface for connecting large language model (LLM) applications to external tools. An MCP tool exposes two semantic views of the same functionality: a developer-provided description that guides the LLM's tool selection, and an implementation that determines the actual runtime behavior. Security issues arise when these two views diverge, leading to instruction injection, misleading descriptions, malicious code, or unsafe implementations. Existing defenses analyze descriptions or implementations largely in isolation, and thus, fail to address this broader threat space in a unified manner.
We present ContractGuard, the first security-oriented framework for bidirectional semantic contract auditing of MCP tools. Our observation is that diverse MCP threats can be unified as violations of a semantic contract between a tool's description and its implementation. ContractGuard combines reachability-aware static analysis with LLM-based cross-view reasoning for auditing. It extracts a tool-specific code slice, generates a code-grounded description, compares it against the developer-provided one, and validates and classifies detected inconsistencies. We evaluate our method on 3,586 MCP tools from 1,000 real-world MCP servers and 5,661 benchmark cases. Our tool uncovers 116 security issues in the wild, including 21 misleading descriptions, 29 instances of potentially malicious code, and 66 unsafe implementations. It achieves 96.0% true positive rate on malicious-code benchmarks, and more than 92.8% true positive rate on description-attack benchmarks. Results show that contract auditing can effectively identify securityrelevant description-implementation mismatches in MCP tools.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper24
- Tree of Attacks: Jailbreaking Black-Box LLMs AutomaticallyAnay Mehrotra, Manolis Zampetakis, Paul Kassianik, Blaine Nelson 等NeurIPS 2024 · 被引用 835 次
- Paraphrasing evades detectors of AI-generated text, but retrieval is an effective defenseKalpesh Krishna, Yixiao Song, Marzena Karpinska, John Wieting 等NeurIPS 2023 · 被引用 657 次
- Formalizing and Benchmarking Prompt Injection Attacks and DefensesYupei Liu, Yuqi Jia, Runpeng Geng, Jinyuan Jia 等USENIX Security 2024 · 被引用 308 次
- Prompt Injection Attack to Tool Selection in LLM AgentsJiawen Shi, Zenghui Yuan, Guiyao Tie, Pan Zhou 等NDSS 2026 · 被引用 181 次
- The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against LLM Jailbreaks and Prompt InjectionsMilad Nasr, Nicholas Carlini, Chawin Sitawarin, Sander V. Schulhoff 等USENIX Security 2026 · 被引用 134 次
相关 Paper
- AgentBound: Securing Execution Boundaries of AI AgentsChristoph Bühler, Matteo Biagiola, Luca Di Grazia, Guido SalvaneschiFSE 2026 · 被引用 1 次
- MCP Security Bench (MSB): Benchmarking Attacks Against Model Context Protocol in LLM AgentsDongsen Zhang, Zekun Li, Xu Luo, Xuannan Liu 等ICLR 2026 · 被引用 47 次
- MCP-SafetyBench: A Benchmark for Safety Evaluation of Large Language Models with Real-World MCP ServersXuanjun Zong, Zhiqi Shen, Lei Wang, Yunshi Lan 等ICLR 2026 · 被引用 34 次
- ProtocolGuard: Detecting Protocol Non-compliance Bugs via LLM-guided Static Analysis and Dynamic VerificationXiangpu Song, Longjia Pei, Jianliang Wu, Yingpei Zeng 等NDSS 2026 · 被引用 3 次
- Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP EcosystemShuli Zhao, Qinsheng Hou, Zihan Zhan, Yanhao Wang 等S&P 2026 · 被引用 20 次
