|
critical
|
—
|
SQL string concatenation detected
|
D
SQL Injection
|
—
|
—
|
Description
SQL string concatenation detected
Code Snippet
"Create a new file or completely overwrite an existing file with new content. " +
Remediation
Use parameterized queries with placeholders
Confidence
high
Rule ID
MCP-D002
|
|
critical
|
—
|
SQL string concatenation detected
|
D
SQL Injection
|
—
|
—
|
Description
SQL string concatenation detected
Code Snippet
console.error(`Updated allowed directories from MCP roots: ${validatedRootDirs.length} valid directo...
Remediation
Use parameterized queries with placeholders
Confidence
high
Rule ID
MCP-D002
|
|
critical
|
—
|
SQL string concatenation detected
|
D
SQL Injection
|
—
|
—
|
Description
SQL string concatenation detected
Code Snippet
const text = `Successfully created directory ${args.path}`;
Remediation
Use parameterized queries with placeholders
Confidence
high
Rule ID
MCP-D002
|
|
critical
|
—
|
SQL string concatenation detected
|
D
SQL Injection
|
—
|
—
|
Description
SQL string concatenation detected
Code Snippet
"Create a new directory or ensure a directory exists. Can create multiple " +
Remediation
Use parameterized queries with placeholders
Confidence
high
Rule ID
MCP-D002
|
|
high
|
—
|
ML classifier detected prompt injection pattern
|
G
Tool Poisoning
|
—
|
—
|
Description
ML classifier detected prompt injection pattern
Code Snippet
' On Windows, enable Developer Mode or run as Administrator to enable symlink tests'
Remediation
Review and sanitize the detected text for potential injection attempts
Confidence
high
Rule ID
MCP-ML-001
|
|
high
|
—
|
Exfiltration pattern detected in tool or code
|
G
Tool Poisoning
|
—
|
—
|
Description
Exfiltration pattern detected in tool or code
Code Snippet
title: "Read File (Deprecated)",
Remediation
Remove instructions that request sensitive data extraction
Confidence
medium
Rule ID
MCP-G006
|
|
high
|
—
|
Extended prompt injection pattern detected
|
G
Tool Poisoning
|
—
|
—
|
Description
Extended prompt injection pattern detected
Code Snippet
// replace the target file atomically and don't follow symlinks.
Remediation
Review and remove suspicious instruction patterns from tool descriptions and code
Confidence
medium
Rule ID
MCP-G004
|
|
high
|
—
|
Exfiltration pattern detected in tool or code
|
G
Tool Poisoning
|
—
|
—
|
Description
Exfiltration pattern detected in tool or code
Code Snippet
// Read file content and normalize line endings
Remediation
Remove instructions that request sensitive data extraction
Confidence
medium
Rule ID
MCP-G006
|
|
high
|
—
|
Extended prompt injection pattern detected
|
G
Tool Poisoning
|
—
|
—
|
Description
Extended prompt injection pattern detected
Code Snippet
// replace the target file atomically and don't follow symlinks.
Remediation
Review and remove suspicious instruction patterns from tool descriptions and code
Confidence
medium
Rule ID
MCP-G004
|
|
medium
|
—
|
Tool description contains suspicious Unicode characters
|
G
Tool Poisoning
|
—
|
—
|
Description
Tool description contains suspicious Unicode characters
Code Snippet
console.log(' ⏭️ Skipping symlink overwrite prevention test - symlinks not supported');
Remediation
Remove Unicode control characters and confusables
Confidence
high
Rule ID
MCP-G002
|
|
medium
|
—
|
Tool description contains suspicious Unicode characters
|
G
Tool Poisoning
|
—
|
—
|
Description
Tool description contains suspicious Unicode characters
Code Snippet
console.log(' ⏭️ Skipping race condition in read operations test - symlinks not supported');
Remediation
Remove Unicode control characters and confusables
Confidence
high
Rule ID
MCP-G002
|
|
medium
|
—
|
Tool description contains suspicious Unicode characters
|
G
Tool Poisoning
|
—
|
—
|
Description
Tool description contains suspicious Unicode characters
Code Snippet
console.log(' ⏭️ Skipping rename symlink test - symlinks not supported');
Remediation
Remove Unicode control characters and confusables
Confidence
high
Rule ID
MCP-G002
|
|
medium
|
—
|
Tool description contains suspicious Unicode characters
|
G
Tool Poisoning
|
—
|
—
|
Description
Tool description contains suspicious Unicode characters
Code Snippet
console.log(' ⏭️ Skipping symlink race condition test - symlinks not supported');
Remediation
Remove Unicode control characters and confusables
Confidence
high
Rule ID
MCP-G002
|
|
medium
|
—
|
Tool description contains suspicious Unicode characters
|
G
Tool Poisoning
|
—
|
—
|
Description
Tool description contains suspicious Unicode characters
Code Snippet
console.log(' ⏭️ Skipping exclusive file creation test - symlinks not supported');
Remediation
Remove Unicode control characters and confusables
Confidence
high
Rule ID
MCP-G002
|
|
medium
|
—
|
Tool description contains suspicious Unicode characters
|
G
Tool Poisoning
|
—
|
—
|
Description
Tool description contains suspicious Unicode characters
Code Snippet
console.log(' ⏭️ Skipping directory creation timing test - symlinks not supported');
Remediation
Remove Unicode control characters and confusables
Confidence
high
Rule ID
MCP-G002
|
|
medium
|
—
|
Tool description contains suspicious Unicode characters
|
G
Tool Poisoning
|
—
|
—
|
Description
Tool description contains suspicious Unicode characters
Code Snippet
console.log(' ⏭️ Skipping timing validation test - symlinks not supported');
Remediation
Remove Unicode control characters and confusables
Confidence
high
Rule ID
MCP-G002
|
|
medium
|
—
|
Tool description contains suspicious Unicode characters
|
G
Tool Poisoning
|
—
|
—
|
Description
Tool description contains suspicious Unicode characters
Code Snippet
console.log(' ⏭️ Skipping resolved parent paths test - symlinks not supported');
Remediation
Remove Unicode control characters and confusables
Confidence
high
Rule ID
MCP-G002
|
|
medium
|
—
|
Tool description contains suspicious Unicode characters
|
G
Tool Poisoning
|
—
|
—
|
Description
Tool description contains suspicious Unicode characters
Code Snippet
console.log(' ⏭️ Skipping parent directory symlink traversal test - symlinks not supported');
Remediation
Remove Unicode control characters and confusables
Confidence
high
Rule ID
MCP-G002
|
|
medium
|
—
|
Tool description contains suspicious Unicode characters
|
G
Tool Poisoning
|
—
|
—
|
Description
Tool description contains suspicious Unicode characters
Code Snippet
console.log(' ⏭️ Skipping race condition prevention test - symlinks not supported');
Remediation
Remove Unicode control characters and confusables
Confidence
high
Rule ID
MCP-G002
|
|
medium
|
—
|
Tool description contains suspicious Unicode characters
|
G
Tool Poisoning
|
—
|
—
|
Description
Tool description contains suspicious Unicode characters
Code Snippet
console.log(' ⏭️ Skipping symlinks within allowed directories test - symlinks not supported')...
Remediation
Remove Unicode control characters and confusables
Confidence
high
Rule ID
MCP-G002
|