Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Your MCP Server Executes Commands - But From Whom? - Advanced Tool-Poisoning Attacks and Zero-Trust Defense

nullcon via YouTube

Overview

Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Explore advanced security vulnerabilities in MCP (Model Context Protocol) servers through this 35-minute conference presentation that demonstrates how attackers can weaponize every byte of data an MCP server transmits. Learn why traditional static prompt-sanitizing methods are inadequate defenses in modern AI agent architectures. Discover the mechanics of classic Tool-Poisoning Attacks (TPA) and understand why simply monitoring description fields provides only superficial security theater. Master Full-Schema Poisoning (FSP) techniques through hands-on fuzzing demonstrations of auto-generated JSON schemas, revealing how malicious payloads can be concealed within parameter names, data types, default values, and required arrays to manipulate LLM reasoning processes. Examine Advanced Tool-Poisoning Attacks (ATPA), a sophisticated post-execution methodology that embeds prompts within runtime error strings to force agents into data leakage and unauthorized remote MCP call chaining while completely bypassing static analysis detection. Gain practical insights into implementing a zero-trust security framework including schema allowlisting, runtime differential auditing, and LLM self-critique mechanisms, while understanding the limitations and ongoing challenges in securing AI agent communications.

Syllabus

#NullconBerlin2025 | Your MCP Server Executes Commands - But From Whom? by Simcha Kosman

Taught by

nullcon

Reviews

Start your review of Your MCP Server Executes Commands - But From Whom? - Advanced Tool-Poisoning Attacks and Zero-Trust Defense

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.