MCP VAPT

MCP Pen Testing & Security

VAPT for Model Context Protocol servers, clients, and agent-to-agent integrations

Continuous AI pen testing for MCP deployments — tool poisoning, prompt injection via tool outputs, OAuth 2.1 / resource indicator validation, confused-deputy chains, multi-tenant isolation, and transport hardening across stdio, HTTP, and streamable HTTP MCP servers.

How It Works

Four steps. One continuous pen testing loop.

1

MCP Surface Discovery

Enumerate every MCP server and client in your stack — hosted (Anthropic, remote HTTP servers) and self-hosted (stdio, SSE, streamable HTTP). Catalogue tools, resources, prompts, and sampling endpoints each server exposes.

2

Tool & Resource Testing

Pen test every MCP tool for injection, authorisation bypass, path traversal, and confused-deputy abuse. Test resources for untrusted content that reaches the model as context — the most common MCP exploitation path in 2026.

3

Auth, Scope, Transport

Validate MCP OAuth 2.1 implementation (PKCE, resource indicators, token audience), scope-based tool authorisation, transport integrity (stdio sandboxing, HTTP TLS, origin validation on streamable HTTP), and session-management edges.

4

Evidence & Remediation

Each finding ships with a working PoC against your specific MCP implementation, remediation guidance for the SDK you're using (Python / TypeScript / Go), and compliance mapping for SOC 2, ISO 27001, HIPAA, and emerging AI-specific controls (ISO 42001, NIST AI RMF).

Key Features

Full Model Context Protocol attack surface coverage

Tool Description Injection

Scan tool metadata (name, description, inputSchema) for injection payloads that reach the model as instructions on tools/list

Tool Output Injection

Validate that tool outputs returned via tools/call are correctly treated as untrusted content by the hosting client

Resource Content Injection

Test resources/read responses for payloads that hijack the model when retrieved as context (the equivalent of stored XSS in MCP terms)

Confused-Deputy Chains

Pen test authorisation flows where a lower-privilege caller tricks a higher-privilege MCP server into performing actions on their behalf

OAuth 2.1 + PKCE

Validate OAuth 2.1 compliance — PKCE enforcement, authorisation code reuse, redirect URI validation, state parameter integrity

Resource Indicators (RFC 8707)

Test token audience binding — confirm tokens issued for one MCP server cannot be replayed against another

Scope-Based Authorisation

Verify that MCP scopes correctly gate tool access and that scope downscoping on token refresh behaves as expected

Session Management

Test session IDs on streamable HTTP transports for predictability, fixation, and lifetime bugs

Origin / DNS Rebinding

Validate origin header enforcement on streamable HTTP MCP servers and resistance to DNS-rebinding attacks against localhost-bound servers

Path Traversal in Resources

Test resources/read URIs for path traversal, SSRF, and arbitrary-file read when URI handling is naive

Multi-Tenant Isolation

In hosted MCP server deployments, validate that one tenant's tool calls, resources, or sampled completions cannot leak into another tenant's context

Secret Exfiltration via Tools

Test for tool-abuse paths where the attacker drives the model into calling tools that exfiltrate secrets (API keys, internal URLs, credentials) via tool arguments or sampled completions

Benefits

Why teams choose TigerStrike for their security needs

MCP-Native Scanning

Built for the Model Context Protocol specification — tests the actual protocol surface (initialize, tools/list, tools/call, resources/list, resources/read, prompts/list, sampling) rather than treating MCP as a generic REST API.

MCP-Native Scanning

Tool Poisoning & Prompt Injection

The dominant MCP risk class: an attacker-controlled tool description or resource content reaches the model as instructions. TigerStrike scans tool metadata, descriptions, parameter schemas, and resource responses for injection payloads that would hijack the hosting agent.

Tool Poisoning & Prompt Injection

Confused Deputy & Scope Escalation

MCP tools inherit the authority of the hosting client. We test for confused-deputy chains — a lower-privilege user convincing a higher-privilege MCP server to perform actions on their behalf — and for scope leakage across multi-tenant MCP deployments.

Confused Deputy & Scope Escalation

OAuth 2.1 / Resource Indicator Validation

MCP's authorisation spec builds on OAuth 2.1 with PKCE, dynamic client registration, and RFC 8707 resource indicators. We validate every claim path — audience binding, token leakage, insufficient scope checks, and the specific MCP-flavoured mistakes that have appeared in production servers.

OAuth 2.1 / Resource Indicator Validation

Multi-Agent Trust Boundary Testing

In agent-to-agent architectures where one agent calls another through MCP, we test the trust boundary — can the calling agent exfiltrate secrets from the callee's tool outputs, can tool poisoning propagate across the chain, and does the receiving agent correctly treat the caller's claims as untrusted input.

Multi-Agent Trust Boundary Testing

Transport & Session Hardening

Test the MCP transport layer — stdio sandboxing on self-hosted servers, TLS on HTTP transports, origin validation on streamable HTTP, session-ID predictability, cross-origin exposure, and the DNS-rebinding paths specific to localhost-bound MCP servers.

Transport & Session Hardening

Frequently Asked Questions

Ready to get started?

Start securing your applications today with TigerStrike's AI-powered penetration testing platform.

Book a Demo