The Model Context Protocol (MCP) lets large language models (LLMs) invoke exter- nal tools through MCP servers. Its adoption has grown rapidly, but security practices have not kept pace: most servers are written by individual developers and the protocol’s best practices are often not followed. This work systematises the existing open-source frameworks for MCP security analysis, characterising their coverage, and designs SAMS, a pipeline that combines them into a single analysis whose raw, low-precision findings are reduced to an actionable set through a three-stage post-processing process (a structural filter, high-confidence rules, and a local LLM for ambiguous cases). Applying SAMS at scale, we conduct the largest security analysis of the MCP ecosystem on 69,104 MCP servers. We find that a substantial fraction of servers exhibit security-relevant issues, ranging from misconfigurations that open the way to vulnerabilities — input validation flaws, dangerous capabilities, sensitive-information disclosure, credential leakage and un- trusted content — to deliberately inserted exploits, including three confirmed trojans. From these results we distil five recurring antipatterns and a set of practical recommen- dations for developers. All code and data are released for reproducibility.
Il Model Context Protocol (MCP) consente ai large language model (LLM) di invocare strumenti esterni attraverso i server MCP. La sua adozione è cresciuta rapidamente, ma le pratiche di sicurezza non hanno tenuto il passo: la maggior parte dei server è scritta da singoli sviluppatori e le best practice del protocollo vengono spesso ignorate. Questo lavoro sistematizza i framework open-source esistenti per l’analisi di sicurezza dei server MCP e ne valuta la copertura. Su questa base progettiamo SAMS, una pipeline che li com- bina in un’unica analisi e ne condensa l’output grezzo e a bassa precisione in un insieme di risultati concreti, attraverso un post-processing in tre fasi: un primo filtro strutturale, un insieme di regole ad alta confidenza e un LLM locale per i casi ambigui. Applicando SAMS su larga scala, realizziamo la più ampia analisi di sicurezza mai condotta sull’ecosistema MCP, su 69.104 server. Emerge che una quota rilevante di essi presenta problemi di si- curezza, che vanno da misconfigurazioni che aprono la strada a vulnerabilità — improper input validation, dangerous capabilities, sensitive-information disclosure, credential leak e untrusted content — fino a exploit inseriti deliberatamente, tra cui tre trojan confermati. Da questi risultati ricaviamo cinque antipattern ricorrenti e una serie di raccomandazioni pratiche per gli sviluppatori. Tutto il codice e i dati sono resi pubblici per garantire la riproducibilità.
How (in)secure are MCP servers? A large-scale security analysis of the MCP ecosystem
MARTIGNONI, FRANCESCO
2025/2026
Abstract
The Model Context Protocol (MCP) lets large language models (LLMs) invoke exter- nal tools through MCP servers. Its adoption has grown rapidly, but security practices have not kept pace: most servers are written by individual developers and the protocol’s best practices are often not followed. This work systematises the existing open-source frameworks for MCP security analysis, characterising their coverage, and designs SAMS, a pipeline that combines them into a single analysis whose raw, low-precision findings are reduced to an actionable set through a three-stage post-processing process (a structural filter, high-confidence rules, and a local LLM for ambiguous cases). Applying SAMS at scale, we conduct the largest security analysis of the MCP ecosystem on 69,104 MCP servers. We find that a substantial fraction of servers exhibit security-relevant issues, ranging from misconfigurations that open the way to vulnerabilities — input validation flaws, dangerous capabilities, sensitive-information disclosure, credential leakage and un- trusted content — to deliberately inserted exploits, including three confirmed trojans. From these results we distil five recurring antipatterns and a set of practical recommen- dations for developers. All code and data are released for reproducibility.| File | Dimensione | Formato | |
|---|---|---|---|
|
Executive_Summary___How__In_secure_Are_MCP_Servers__A_Large_Scale_Security_Analysis_of_the_MCP_Ecosystem.pdf
accessibile in internet per tutti
Descrizione: Executive Summary
Dimensione
552.8 kB
Formato
Adobe PDF
|
552.8 kB | Adobe PDF | Visualizza/Apri |
|
How__In_secure_Are_MCP_Servers__A_Large_Scale_Security_Analysis_of_the_MCP_Ecosystem.pdf
accessibile in internet per tutti
Descrizione: Tesi
Dimensione
937.26 kB
Formato
Adobe PDF
|
937.26 kB | Adobe PDF | Visualizza/Apri |
I documenti in POLITesi sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.
https://hdl.handle.net/10589/260118