MCP Security Scan Threat Categories in Tencent AI-Infra-Guard: Complete Taxonomy Guide

The Tencent AI-Infra-Guard MCP scanner evaluates Model Context Protocol servers against 15 distinct threat categories—including Tool Poisoning, SSRF, SQL Injection, and Prompt Injection—defined as declarative YAML rules in data/mcp/.

The Tencent/AI-Infra-Guard open-source project provides specialized security scanning capabilities for AI infrastructure, with dedicated evaluation logic for MCP security scans targeting Model Context Protocol implementations. The scanner employs a comprehensive threat taxonomy that evaluates server configurations and tool definitions against predefined vulnerability patterns. Each category represents a specific attack vector against AI agent integrations, encoded as individual YAML rule files that the Go-based engine processes during analysis.

The 15 MCP Threat Categories

The AI-Infra-Guard MCP scanner organizes vulnerabilities into a structured taxonomy covering injection attacks, data integrity risks, access control failures, and infrastructure exploits. These MCP security scan threat categories are implemented as separate YAML configuration files under data/mcp/, loaded dynamically by internal/mcp/scanner.go during execution.

Injection and Execution Threats

Command Injection (mcp_command_injection.yaml): Detects execution of arbitrary system commands via improperly sanitized inputs passed to MCP tools. This category identifies when user-controlled data reaches shell execution contexts without adequate validation.

SQL Injection (mcp_sql_injection.yaml): Identifies improper handling of SQL statements within MCP server implementations, allowing attackers to manipulate database queries through tool parameters or resource identifiers.

Prompt Injection via Tool Results (mcp_prompt_injection_tool_results.yaml): Detects malicious content injected through tool-generated outputs that subsequently become prompts for the AI model, potentially hijacking agent behavior.

Resource Prompt Injection (mcp_resource_prompt_injection.yaml): Flags untrusted prompts that influence the MCP's resource handling mechanisms, allowing manipulation of how the server accesses or processes external data.

Data Integrity and Supply Chain Risks

Tool Poisoning (tool_poisoning.yaml): Identifies malicious or manipulated tool definitions that can corrupt AI Agent behavior, including tampered tool schemas or descriptions designed to mislead the model.

Tool Rug Pull (mcp_tool_rug_pull.yaml): Detects "rug-pull" scenarios where a tool's implementation is swapped with malicious code after initial deployment, compromising previously trusted integrations.

Unsafe Deserialization (mcp_unsafe_deserialization.yaml): Flags deserialization of untrusted data that may lead to remote code execution, particularly when MCP servers process serialized objects from external sources.

Insecure Deserialization (mcp_insecure_deserialization.yaml): Covers generic deserialization vulnerabilities that can be exploited to manipulate object states or execute arbitrary code during the deserialization process.

Access Control and Secrets Management

Missing Authentication (mcp_missing_authentication.yaml): Identifies the absence of proper authentication checks on MCP endpoints, allowing unauthorized access to sensitive tool capabilities or resources.

Hard-coded Secrets (mcp_hardcoded_secrets.yaml): Detects embedded credentials, tokens, or passwords within MCP server code or configuration files, exposing sensitive authentication material.

Excessive Permissions (mcp_excessive_permissions.yaml): Flags over-privileged access granted to the MCP server or its individual tools, violating the principle of least privilege.

Credential Exfiltration (mcp_credential_exfiltration.yaml): Identifies leakage of credentials through MCP responses, logs, or error messages that could expose sensitive authentication data to attackers.

Network and Infrastructure Attacks

Server-Side Request Forgery (SSRF) (mcp_ssrf.yaml): Detects when MCP servers can be tricked into making unauthorized internal network requests, potentially accessing cloud metadata services or internal APIs.

Path Traversal (mcp_path_traversal.yaml): Identifies path manipulation vulnerabilities allowing access to files outside intended directories, commonly exploited through malicious resource identifiers.

Cross-Origin Resource Sharing (CORS) (cors.yaml): Flags misconfigured CORS policies that allow unauthorized cross-origin requests to MCP endpoints, potentially enabling browser-based attacks against the server.

Implementation Architecture

The threat categories are implemented through a modular rule engine defined in internal/mcp/scanner.go. During a scan operation, the engine iterates through the data/mcp/ directory, loading each YAML rule file to evaluate the target MCP server against that specific threat category.

To inspect the available threat rules locally:

ls -la data/mcp/

Each YAML file contains the detection logic for its respective category, allowing security teams to understand exactly which patterns trigger specific vulnerability reports. The scanner correlates detected issues with their respective categories, enabling prioritized remediation based on the specific threat type.

Summary

  • The Tencent AI-Infra-Guard MCP security scan evaluates servers against 15 predefined threat categories ranging from injection attacks to infrastructure misconfigurations.
  • Each category is defined as a separate YAML rule file in data/mcp/, with names like mcp_sql_injection.yaml and tool_poisoning.yaml.
  • The Go-based scanner (internal/mcp/scanner.go) dynamically loads these rules to perform comprehensive security assessments of MCP implementations.
  • Categories cover Prompt Injection, Command Injection, SSRF, Path Traversal, Hard-coded Secrets, and supply chain risks like Tool Rug Pull.

Frequently Asked Questions

What distinguishes Tool Poisoning from Tool Rug Pull in MCP security scans?

Tool Poisoning (tool_poisoning.yaml) detects malicious tool definitions that corrupt AI agent behavior through tampered schemas or descriptions, while Tool Rug Pull (mcp_tool_rug_pull.yaml) identifies runtime replacement of legitimate tool implementations with malicious code after deployment. The former targets static configuration integrity, whereas the latter detects dynamic supply chain compromises.

How does the AI-Infra-Guard scanner detect Prompt Injection vulnerabilities?

The scanner uses two specialized categories: Resource Prompt Injection (mcp_resource_prompt_injection.yaml) for untrusted prompts influencing resource handling, and Prompt Injection Tool Results (mcp_prompt_injection_tool_results.yaml) for malicious content injected via tool outputs that become subsequent prompts. Both rules analyze how external data flows into model contexts.

Can organizations customize or extend the MCP threat categories?

While the base taxonomy is defined in the data/mcp/ YAML files, the modular architecture in internal/mcp/scanner.go supports extending coverage by adding new rule files to the directory. Organizations can create custom YAML definitions following the existing schema to detect domain-specific threats beyond the 15 standard categories.

Which threat categories pose the highest risk for publicly exposed MCP servers?

Missing Authentication (mcp_missing_authentication.yaml) and SSRF (mcp_ssrf.yaml) typically present critical risks for public endpoints, as unauthenticated access combined with server-side request forgery can lead to internal network compromise. Command Injection (mcp_command_injection.yaml) and Credential Exfiltration (mcp_credential_exfiltration.yaml) also rank high due to their potential for immediate data breaches or infrastructure takeover.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →