[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83246-en":3,"doc-seo-83246-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83246,962075114101,"Seraphina","https://ap-avatar.wpscdn.com/avatar/e000253a75eb197efd?x-image-process=image/resize,m_fixed,w_180,h_180&k=1780044092746381165",8,"Research & Report","Mitigating Taint-Style Vulnerabilities in MCP Servers via Security-Aware Tool Descriptions","Large language models (LLMs) are increasingly used as autonomous agents interacting with external tools through the Model Context Protocol (MCP). While MCP standardizes tool invocation, it broadens the attack surface and can enable reusable exploits across servers. This work systematically analyzes MCP server vulnerabilities using metadata traits, vulnerable code patterns, and community response, finding taint-style issues form a large share, need major code changes, and face slow remediation. To address this, SPELLSMITH builds tool-level risk profiles and mitigates via description enhancement and LLM self-reflection.","Mitigating Taint-Style Vulnerabilities in MCP Servers via Security-Aware Tool  \nDescriptions  \nYang Shi Jiaheng Fu Yihe Huang Ruixiang Wu Chengyao Sun Kaifeng Huang  \nTongji University  \n{shiyang,jiahengfu,huangyihe, [rxwu}@tongji.edu.cn](rxwu}@tongji.edu.cn)[ ](rxwu}@tongji.edu.cn){2452523, [kaifengh}@tongji.edu.cn](kaifengh}@tongji.edu.cn)  \narXiv :2607 .0746 1v 1 [ cs .CR] 8 Jul 2026  \nAbstract  \nLarge language models (LLMs) are increasingly deployed as autonomous agents that interact with external tools and services via the Model Context Protocol (MCP), a standardized interface for dynamic tool invocation. While MCP simplifies integration, it also expands the attack surface and enables generic exploits across multiple servers. Despite prior work on malicious MCP servers, the vulnerability landscape of MCP servers remains underexplored. In this work, we systematically analyze MCP server vulnerabilities, focusing on metadata characteristics, vulnerable code patterns, and community responses. Our study reveals that taint-style vulnerabilities constitute a substantial fraction of MCP server vulnerabilities, require significant code modifications to remediate, and are met with slow community responses. Motivated by these findings, we propose SPELLSMITH, presenting a novel textbased avenue for shielding taint-style vulnerabilities in MCP servers. In particular, SPELLSMITH analyzes the high-risk capabilities exposed by an MCP server and combines them with tool descriptions and parameter semantics to identify potential taint-style vulnerability risks, thereby constructing a tool-level risk profile. Then, SPELLSMITH leverages the Description property of the protocol to embed behavioral guidance (Description Enhancement Module) and exploits LLMs’ self-reflection capabilities (Self-Reflection Module) to iteratively evaluate and refine outputs. By strengthening LLM internal decision-making, SPELLSMITH provides an active and unified mitigation strategy that generalizes across multiple vulnerabilities, reducing reliance on context-specific code-level fixes. Our experiments demonstrate that SPELLSMITH effectively mitigates taint-style vulnerability exploitation in MCP servers, highlighting its practical applicability and advantages over traditional code-level mitigations.  \n1 Introduction  \nLarge language models (LLMs) are increasingly deployed as autonomous or semi-autonomous agents that interact with  \nexternal tools, services, and data sources to accomplish complex tasks. To standardize and simplify these interactions, the Model Context Protocol (MCP) [2] has recently emerged asa unifying interface that allows LLMs to dynamically discover and invoke external tools or services through MCP servers. Companies are actively deploying MCP servers to enable integration with and usage of their products. For example, Notion provides a connector for AI to interact directly with workspace databases [3]; and Google delivers dedicated servers that integrate AI across its suite of Drive, Gmail, and Calendar services [1] .  \nHowever, the MCP paradigm also introduces new security challenges. On the one hand, the shift toward external interactions expands the attack surface of LLM-based systems. On the other hand, the standardization of the protocol design makes it easier for attackers to craft generic exploits that can target multiple MCP servers.  \nSeveral existing works focus on characterizing malicious MCP servers [11, 12] or presenting malicious MCP server proof-of-concepts [47, 49] . However, the vulnerabilities of MCP servers remain under-investigated. To bridge this gap, we first systematically study the vulnerability landscape of MCP servers. We begin by collecting and analyzing all MCP server vulnerabilities disclosed in the National Vulnerability Database (NVD) to date. We then design and conduct three research questions: Metadata Characteristics (RQ1) , Vulnerability and Repair Property (RQ2), and Response of Vulnerabilities (RQ3), to unde","cbCaihcg3dvwt7Wk","https://ap.wps.com/l/cbCaihcg3dvwt7Wk","pdf",1016577,4,1,14,"English","en",105,"# Abstract\n# Introduction","[{\"question\":\"What problem does this paper address in MCP server deployments?\",\"answer\":\"It addresses how MCP-enabled LLM agents enlarge the security attack surface and how MCP servers contain vulnerabilities that remain underexplored despite existing work on malicious servers and proofs of concept.\"},{\"question\":\"What is the key finding about vulnerability types in MCP servers?\",\"answer\":\"The study finds taint-style vulnerabilities make up a substantial fraction (81.13%) of disclosed MCP server vulnerabilities and typically require significant code modifications and longer remediation timelines.\"},{\"question\":\"How does SPELLSMITH mitigate taint-style vulnerabilities in MCP servers?\",\"answer\":\"SPELLSMITH analyzes high-risk capabilities exposed by an MCP server, combines them with tool descriptions and parameter semantics to create a tool-level risk profile, then embeds behavioral guidance into the protocol Description and uses LLM self-reflection to iteratively evaluate and refine mitigation outputs.\"}]",1784186225,35,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"mitigating-taint-style-vulnerabilities-in-mcp-servers-via-security-aware-tool-descriptions","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":20},"https://docshare.wps.com/document/mitigating-taint-style-vulnerabilities-in-mcp-servers-via-security-aware-tool-descriptions/83246/",{"url":52,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-24","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does this paper address in MCP server deployments?","Question",{"text":75,"@type":76},"It addresses how MCP-enabled LLM agents enlarge the security attack surface and how MCP servers contain vulnerabilities that remain underexplored despite existing work on malicious servers and proofs of concept.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What is the key finding about vulnerability types in MCP servers?",{"text":80,"@type":76},"The study finds taint-style vulnerabilities make up a substantial fraction (81.13%) of disclosed MCP server vulnerabilities and typically require significant code modifications and longer remediation timelines.",{"name":82,"@type":73,"acceptedAnswer":83},"How does SPELLSMITH mitigate taint-style vulnerabilities in MCP servers?",{"text":84,"@type":76},"SPELLSMITH analyzes high-risk capabilities exposed by an MCP server, combines them with tool descriptions and parameter semantics to create a tool-level risk profile, then embeds behavioral guidance into the protocol Description and uses LLM self-reflection to iteratively evaluate and refine mitigation outputs.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]