Mcp ExploitationTier 2critical
MCP Exploitation: Tool Injection
Attacks targeting Model Context Protocol integrations
Fake tool results inject false information into the agent's reasoning process by mimicking the output format of legitimate MCP tools.
Attack Details
- Attack ID
- APWN-MCP-002
- HMA Check
- MCP-002
- Delivery Methods
- html-comment, invisible-span
- CWE
- CWE-74
- OASB Control
- 7.2
- Severity
- critical
Remediation
If your AI agent is vulnerable to this attack, scan and fix with:
npx hackmyagent secure --check MCP-002