MCP Pen Testing & Security
VAPT for Model Context Protocol servers, clients, and agent-to-agent integrations
Continuous AI pen testing for MCP deployments — tool poisoning, prompt injection via tool outputs, OAuth 2.1 / resource indicator validation, confused-deputy chains, multi-tenant isolation, and transport hardening across stdio, HTTP, and streamable HTTP MCP servers.
Four steps. One continuous pen testing loop.
MCP Surface Discovery
Enumerate every MCP server and client in your stack — hosted (Anthropic, remote HTTP servers) and self-hosted (stdio, SSE, streamable HTTP). Catalogue tools, resources, prompts, and sampling endpoints each server exposes.
Tool & Resource Testing
Pen test every MCP tool for injection, authorisation bypass, path traversal, and confused-deputy abuse. Test resources for untrusted content that reaches the model as context — the most common MCP exploitation path in 2026.
Auth, Scope, Transport
Validate MCP OAuth 2.1 implementation (PKCE, resource indicators, token audience), scope-based tool authorisation, transport integrity (stdio sandboxing, HTTP TLS, origin validation on streamable HTTP), and session-management edges.
Evidence & Remediation
Each finding ships with a working PoC against your specific MCP implementation, remediation guidance for the SDK you're using (Python / TypeScript / Go), and compliance mapping for SOC 2, ISO 27001, HIPAA, and emerging AI-specific controls (ISO 42001, NIST AI RMF).
Key Features
Full Model Context Protocol attack surface coverage
Tool Description Injection
Scan tool metadata (name, description, inputSchema) for injection payloads that reach the model as instructions on tools/list
Tool Output Injection
Validate that tool outputs returned via tools/call are correctly treated as untrusted content by the hosting client
Resource Content Injection
Test resources/read responses for payloads that hijack the model when retrieved as context (the equivalent of stored XSS in MCP terms)
Confused-Deputy Chains
Pen test authorisation flows where a lower-privilege caller tricks a higher-privilege MCP server into performing actions on their behalf
OAuth 2.1 + PKCE
Validate OAuth 2.1 compliance — PKCE enforcement, authorisation code reuse, redirect URI validation, state parameter integrity
Resource Indicators (RFC 8707)
Test token audience binding — confirm tokens issued for one MCP server cannot be replayed against another
Scope-Based Authorisation
Verify that MCP scopes correctly gate tool access and that scope downscoping on token refresh behaves as expected
Session Management
Test session IDs on streamable HTTP transports for predictability, fixation, and lifetime bugs
Origin / DNS Rebinding
Validate origin header enforcement on streamable HTTP MCP servers and resistance to DNS-rebinding attacks against localhost-bound servers
Path Traversal in Resources
Test resources/read URIs for path traversal, SSRF, and arbitrary-file read when URI handling is naive
Multi-Tenant Isolation
In hosted MCP server deployments, validate that one tenant's tool calls, resources, or sampled completions cannot leak into another tenant's context
Secret Exfiltration via Tools
Test for tool-abuse paths where the attacker drives the model into calling tools that exfiltrate secrets (API keys, internal URLs, credentials) via tool arguments or sampled completions
Benefits
Why teams choose TigerStrike for their security needs
MCP-Native Scanning
Built for the Model Context Protocol specification — tests the actual protocol surface (initialize, tools/list, tools/call, resources/list, resources/read, prompts/list, sampling) rather than treating MCP as a generic REST API.

Tool Poisoning & Prompt Injection
The dominant MCP risk class: an attacker-controlled tool description or resource content reaches the model as instructions. TigerStrike scans tool metadata, descriptions, parameter schemas, and resource responses for injection payloads that would hijack the hosting agent.

Confused Deputy & Scope Escalation
MCP tools inherit the authority of the hosting client. We test for confused-deputy chains — a lower-privilege user convincing a higher-privilege MCP server to perform actions on their behalf — and for scope leakage across multi-tenant MCP deployments.

OAuth 2.1 / Resource Indicator Validation
MCP's authorisation spec builds on OAuth 2.1 with PKCE, dynamic client registration, and RFC 8707 resource indicators. We validate every claim path — audience binding, token leakage, insufficient scope checks, and the specific MCP-flavoured mistakes that have appeared in production servers.

Multi-Agent Trust Boundary Testing
In agent-to-agent architectures where one agent calls another through MCP, we test the trust boundary — can the calling agent exfiltrate secrets from the callee's tool outputs, can tool poisoning propagate across the chain, and does the receiving agent correctly treat the caller's claims as untrusted input.

Transport & Session Hardening
Test the MCP transport layer — stdio sandboxing on self-hosted servers, TLS on HTTP transports, origin validation on streamable HTTP, session-ID predictability, cross-origin exposure, and the DNS-rebinding paths specific to localhost-bound MCP servers.

Frequently Asked Questions
Ready to get started?
Start securing your applications today with TigerStrike's AI-powered penetration testing platform.
Book a Demo