Skip to main content

AGENTFORCE-MCP-13: MCP Tool Can Change Its Own Safety Configuration

๐Ÿ”ด High ยท MCP Supply Chain

Detects MCP tools (set_config_value, update_settings, ...) that let the model rewrite the server's own safety settings such as blocked commands, allowed directories or approval requirements, so a prompt injection can switch the guardrails off before using other tools.

Detailsโ€‹

FieldValue
Rule IDAGENTFORCE-MCP-13
SeverityHigh
CategoryMCP Supply Chain

Remediationโ€‹

Make safety keys (command blocklists/allowlists, allowed directories, approval and sandbox flags) read-only to tools: reject them in the config tool, or require out-of-band user confirmation (CLI flag, config file edit, UI prompt) to change them.

See Alsoโ€‹