AGENTFORCE-MCP-13: MCP Tool Can Change Its Own Safety Configuration
๐ด High ยท MCP Supply Chain
Detects MCP tools (set_config_value, update_settings, ...) that let the model rewrite the server's own safety settings such as blocked commands, allowed directories or approval requirements, so a prompt injection can switch the guardrails off before using other tools.
Detailsโ
| Field | Value |
|---|---|
| Rule ID | AGENTFORCE-MCP-13 |
| Severity | High |
| Category | MCP Supply Chain |
Remediationโ
Make safety keys (command blocklists/allowlists, allowed directories, approval and sandbox flags) read-only to tools: reject them in the config tool, or require out-of-band user confirmation (CLI flag, config file edit, UI prompt) to change them.