Glossary · term
MCP Sampling Attacks
An attack vector arising from the sampling feature in MCP, which lets a server initiate queries to the client's model, reversing the typical direction of interaction. A malicious or compromised server can abuse the model in this way to steal resources and API quota, inject persistent instructions that hijack the conversation, or invoke tools (writing files, exfiltration) without the user's consent.
Safety2026Wave 3 · 2025–26Maturity: 4/5
Maturity rationale
Palo Alto Unit 42 security research
References
Author: Społeczność / Anonimowi