{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:XELYRJNCAAJX3W3V64PIQXGSXP","short_pith_number":"pith:XELYRJNC","schema_version":"1.0","canonical_sha256":"b91788a5a200137ddb75f71e885cd2bbc83d14377f996e2fa5e1beb0d3781711","source":{"kind":"arxiv","id":"2508.14925","version":1},"attestation_state":"computed","paper":{"title":"MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Guanquan Shi, Haifeng Sun, Haohua Du, Haoran Cheng, Suyuan Liu, Xiangyang Li, Yanting Wang, Yichao Gao, Zhiqiang Wang","submitted_at":"2025-08-19T10:12:35Z","abstract_excerpt":"By providing a standardized interface for LLM agents to interact with external tools, the Model Context Protocol (MCP) is quickly becoming a cornerstone of the modern autonomous agent ecosystem. However, it creates novel attack surfaces due to untrusted external tools. While prior work has focused on attacks injected through external tool outputs, we investigate a more fundamental vulnerability: Tool Poisoning, where malicious instructions are embedded within a tool's metadata without execution. To date, this threat has been primarily demonstrated through isolated cases, lacking a systematic, "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2508.14925","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2025-08-19T10:12:35Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"48d0430c937ccf1044b3d778ef9617097585ff277dc522b572930ef03aa183c3","abstract_canon_sha256":"ac9b391161ee31e3a192e7cae04faa6d444f3651058c1230c1e30a99dcf4521b"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:57:03.552073Z","signature_b64":"8zZvXhmVW3FJ8ai+2akHvnkeJ0s9naIl5okk2d0ng2tDoPmTwxAjM5c9QxAPMwhg9kRX1O6+psVa4lZ7zgQyAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b91788a5a200137ddb75f71e885cd2bbc83d14377f996e2fa5e1beb0d3781711","last_reissued_at":"2026-07-05T11:57:03.551583Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:57:03.551583Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Guanquan Shi, Haifeng Sun, Haohua Du, Haoran Cheng, Suyuan Liu, Xiangyang Li, Yanting Wang, Yichao Gao, Zhiqiang Wang","submitted_at":"2025-08-19T10:12:35Z","abstract_excerpt":"By providing a standardized interface for LLM agents to interact with external tools, the Model Context Protocol (MCP) is quickly becoming a cornerstone of the modern autonomous agent ecosystem. However, it creates novel attack surfaces due to untrusted external tools. While prior work has focused on attacks injected through external tool outputs, we investigate a more fundamental vulnerability: Tool Poisoning, where malicious instructions are embedded within a tool's metadata without execution. To date, this threat has been primarily demonstrated through isolated cases, lacking a systematic, "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2508.14925","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2508.14925/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2508.14925","created_at":"2026-07-05T11:57:03.551652+00:00"},{"alias_kind":"arxiv_version","alias_value":"2508.14925v1","created_at":"2026-07-05T11:57:03.551652+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2508.14925","created_at":"2026-07-05T11:57:03.551652+00:00"},{"alias_kind":"pith_short_12","alias_value":"XELYRJNCAAJX","created_at":"2026-07-05T11:57:03.551652+00:00"},{"alias_kind":"pith_short_16","alias_value":"XELYRJNCAAJX3W3V","created_at":"2026-07-05T11:57:03.551652+00:00"},{"alias_kind":"pith_short_8","alias_value":"XELYRJNC","created_at":"2026-07-05T11:57:03.551652+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":25,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2607.05744","citing_title":"Unicode TAG-Block Concealment of Tool-Metadata Payloads in the Model Context Protocol: An Approval-View Fidelity Gap Across Three Independent Server Implementations","ref_index":10,"is_internal_anchor":true},{"citing_arxiv_id":"2606.22504","citing_title":"Lingering Authority: Revocable Resource-and-Effect Capabilities for Coding Agents","ref_index":51,"is_internal_anchor":false},{"citing_arxiv_id":"2606.20922","citing_title":"Think Twice Before You Act: Protecting LLM Agents Against Tool Description Poisoning via Isolated Planning","ref_index":2,"is_internal_anchor":false},{"citing_arxiv_id":"2606.04769","citing_title":"Description-Code Inconsistency in Real-world MCP Servers: Measurement, Detection, and Security Implications","ref_index":5,"is_internal_anchor":false},{"citing_arxiv_id":"2606.02668","citing_title":"What You Approve Is What Executes: Consent Integrity for Black-Box LLM Agents","ref_index":12,"is_internal_anchor":false},{"citing_arxiv_id":"2605.24069","citing_title":"When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents","ref_index":13,"is_internal_anchor":false},{"citing_arxiv_id":"2606.00566","citing_title":"Same Payload, Different Channel: Measuring Trust Asymmetry in Tool-Using Language Models","ref_index":1,"is_internal_anchor":false},{"citing_arxiv_id":"2605.11053","citing_title":"Content-Aware Attack Detection in LLM Agent Tool-Call Traffic: An Empirical Study of Features, Architectures, and Evaluation Protocols","ref_index":2,"is_internal_anchor":false},{"citing_arxiv_id":"2605.23330","citing_title":"Security, Privacy, and Ethical Risks in OpenClaw","ref_index":20,"is_internal_anchor":false},{"citing_arxiv_id":"2605.16471","citing_title":"From AI-Generated Content to Agentic Action: Security and Safety Threats in Generative AI","ref_index":137,"is_internal_anchor":false},{"citing_arxiv_id":"2605.17453","citing_title":"Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback","ref_index":10,"is_internal_anchor":false},{"citing_arxiv_id":"2509.06572","citing_title":"Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP Ecosystem","ref_index":48,"is_internal_anchor":false},{"citing_arxiv_id":"2603.13417","citing_title":"Bridging Protocol and Production: Design Patterns for Deploying AI Agents with Model Context Protocol","ref_index":13,"is_internal_anchor":false},{"citing_arxiv_id":"2605.11053","citing_title":"Content-Aware Attack Detection in LLM Agent Tool-Call Traffic: An Empirical Study of Features, Architectures, and Evaluation Protocols","ref_index":2,"is_internal_anchor":false},{"citing_arxiv_id":"2604.03131","citing_title":"A Systematic Security Evaluation of OpenClaw and Its Variants","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2605.11781","citing_title":"Five Attacks on x402 Agentic Payment Protocol","ref_index":19,"is_internal_anchor":false},{"citing_arxiv_id":"2605.11053","citing_title":"Content-Aware Attack Detection in LLM Agent Tool-Call Traffic: An Empirical Study of Features, Architectures, and Evaluation Protocols","ref_index":2,"is_internal_anchor":false},{"citing_arxiv_id":"2605.09822","citing_title":"Oracle Poisoning: Corrupting Knowledge Graphs to Weaponise AI Agent Reasoning","ref_index":25,"is_internal_anchor":false},{"citing_arxiv_id":"2604.11790","citing_title":"ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection","ref_index":40,"is_internal_anchor":false},{"citing_arxiv_id":"2604.11790","citing_title":"ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection","ref_index":40,"is_internal_anchor":false},{"citing_arxiv_id":"2604.04759","citing_title":"Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw","ref_index":17,"is_internal_anchor":false},{"citing_arxiv_id":"2604.05969","citing_title":"A Formal Security Framework for MCP-Based AI Agents: Threat Taxonomy, Verification Models, and Defense Mechanisms","ref_index":10,"is_internal_anchor":false},{"citing_arxiv_id":"2604.04426","citing_title":"ShieldNet: Network-Level Guardrails against Emerging Supply-Chain Injections in Agentic Systems","ref_index":8,"is_internal_anchor":false},{"citing_arxiv_id":"2604.07551","citing_title":"MCP-DPT: A Defense-Placement Taxonomy and Coverage Analysis for Model Context Protocol Security","ref_index":54,"is_internal_anchor":false},{"citing_arxiv_id":"2604.17125","citing_title":"CASCADE: A Cascaded Hybrid Defense Architecture for Prompt Injection Detection in MCP-Based Systems","ref_index":6,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/XELYRJNCAAJX3W3V64PIQXGSXP","json":"https://pith.science/pith/XELYRJNCAAJX3W3V64PIQXGSXP.json","graph_json":"https://pith.science/api/pith-number/XELYRJNCAAJX3W3V64PIQXGSXP/graph.json","events_json":"https://pith.science/api/pith-number/XELYRJNCAAJX3W3V64PIQXGSXP/events.json","paper":"https://pith.science/paper/XELYRJNC"},"agent_actions":{"view_html":"https://pith.science/pith/XELYRJNCAAJX3W3V64PIQXGSXP","download_json":"https://pith.science/pith/XELYRJNCAAJX3W3V64PIQXGSXP.json","view_paper":"https://pith.science/paper/XELYRJNC","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2508.14925&json=true","fetch_graph":"https://pith.science/api/pith-number/XELYRJNCAAJX3W3V64PIQXGSXP/graph.json","fetch_events":"https://pith.science/api/pith-number/XELYRJNCAAJX3W3V64PIQXGSXP/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/XELYRJNCAAJX3W3V64PIQXGSXP/action/timestamp_anchor","attest_storage":"https://pith.science/pith/XELYRJNCAAJX3W3V64PIQXGSXP/action/storage_attestation","attest_author":"https://pith.science/pith/XELYRJNCAAJX3W3V64PIQXGSXP/action/author_attestation","sign_citation":"https://pith.science/pith/XELYRJNCAAJX3W3V64PIQXGSXP/action/citation_signature","submit_replication":"https://pith.science/pith/XELYRJNCAAJX3W3V64PIQXGSXP/action/replication_record"}},"created_at":"2026-07-05T11:57:03.551652+00:00","updated_at":"2026-07-05T11:57:03.551652+00:00"}