Agent 与自动化 4.0 · 优秀 2026-07-07 · 论文

Unicode TAG-Block Concealment of Tool-Metadata Payloads in the Model Context Protocol: An Approv...

论文揭示 MCP 审批视图保真度缺口:工具元数据在一次性人工审批弹窗中的渲染与每轮注入模型的字节并不要求一致;Unicode TAG 区(U+E0000-U+E007F)无字形,写入其中的负载人眼不可见模型可读;作者用无模型分析在三个独立 MCP server 实现上验证

打开原文回到归档

Unicode TAG-Block Concealment of Tool-Metadata Payloads in the Model Context Protocol: An Approval-View Fidelity Gap Across Three Independent Server Implementations

中文导读

论文揭示 MCP 审批视图保真度缺口:工具元数据在一次性人工审批弹窗中的渲染与每轮注入模型的字节并不要求一致;Unicode TAG 区(U+E0000-U+E007F)无字形,写入其中的负载人眼不可见模型可读;作者用无模型分析在三个独立 MCP server 实现上验证

为什么值得关注

论文揭示 MCP 审批视图保真度缺口:工具元数据在一次性人工审批弹窗中的渲染与每轮注入模型的字节并不要求一致;Unicode TAG 区(U+E0000-U+E007F)无字形,写入其中的负载人眼不可见模型可读;作者用无模型分析在三个独立 MCP server 实现上验证

Grounding: model-free, protocol-free analysis shows Unicode's TAG block (U+E0000-U+E007F) has no assigned glyph in mainstream terminal/chat/IDE renderers; a proof-of-concept speaks the real MCP JSON-RPC/stdio protocol against a genuine client and server.

关键信息

  • 论文标题: Unicode TAG-Block Concealment of Tool-Metadata Payloads in the Model Context Protocol: An Approval-View Fidelity Gap Across Three Independent Server Implementations
  • 作者: Mohammadreza Rashidi
  • arXiv: https://arxiv.org/abs/2607.05744
  • 发布时间: 2026-07-07
  • arXiv 分类: cs.CR, cs.AI, cs.SE
  • 关联标签: mcp, security, tool-metadata, arxiv

English Abstract

The Model Context Protocol (MCP) is the dominant way coding agents discover and invoke external tools. A server advertises each tool through a tools/list handshake that returns a name, a natural-language description, and a JSON input schema. The client renders this metadata once, in a one-time approval dialog, and then injects it verbatim into the model's context on every subsequent turn. Nothing in the protocol requires the rendered approval view and the bytes delivered to the model to match. We isolate that gap as a single structural mechanism, concealment encoding, and show with a model-free, protocol-free analysis that Unicode's TAG block (U+E0000 to U+E007F) has no assigned glyph in any mainstream terminal, chat, or IDE renderer, so a payload written in it is absent from what a human reviewer sees while surviving byte-for-byte into the model's tokenizer. We then measure whether this mechanism actually defeats today's client-side defenses, building a proof-of-concept that speaks the real MCP JSON-RPC/stdio protocol against a genuine client and server. Across 5 distinct MCP metadata surfaces we implement 8 concrete techniques with a deterministic, protocol-level harness. All 8/8 techniques deliver an attacker-controlled payload into the model's context, 4/8 evade a representative string-matching sanitizer, and exactly as the mechanism analysis predicts, only the TAG-block encoding (1/8) is invisible in the human approval view while still reaching the model verbatim. MCP forces re-approval for 0/8 techniques even under a time-of-check to time-of-use rug-pull. To test whether these outcomes are a property of the protocol or an artifact of one server codebase, we re-implement the catalogue against 3 independently developed Python MCP server libraries and find total agreement across all 32 cross-library outcome cells. The baseline sanitizer flags 0 of 25 benign descriptions.

English Summary

The paper isolates a structural gap in MCP: nothing requires the tool metadata rendered in the one-time human approval dialog to match the bytes injected into model context on every subsequent turn. Unicode's TAG block (U+E0000-U+E007F) renders no glyph in mainstream terminals, chat, or IDE clients, so payloads written in it are invisible to the human approver but fully readable by the model, verified model-free across three independent MCP server implementations.

Obsidian Notes

  • 内容由 opencli arxiv paper 拉取 arXiv 元数据与摘要生成。
  • 中文导读与价值判断均锚定在条目已有摘要、论文摘要、作者、日期与分类信息上;未补充论文摘要之外的实验细节。