Servant, Stalker, Predator: How An Honest, Helpful, And Harmless (3H) Agent Unlocks Adversarial Skills

📅 2025-08-26
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This paper identifies a novel class of cross-domain compositional vulnerabilities in Model Context Protocol (MCP)-based agent systems: malicious orchestration of otherwise legitimate, authorized agent services can violate service isolation assumptions and produce harmful emergent behaviors. Method: We introduce and empirically validate the “cross-domain service coordination attack” threat model, leveraging MITRE ATLAS for systematic red-teaming; attacks integrate multimodal capabilities—including browser automation, financial analysis, geolocation tracking, and code deployment—across heterogeneous domains. Contribution/Results: We demonstrate that current MCP architectures lack cross-domain security monitoring and coordination constraints, causing the attack surface to scale exponentially with the number of available capabilities. Our experiments show that a fully compliant chain of only 95 authorized agents suffices to execute end-to-end attacks—including data exfiltration, financial manipulation, and infrastructure compromise—exposing a fundamental deficiency in MCP’s cross-domain protection design.

Technology Category

Multiagent Systems: Coordination and CollaborationApplication Domains: SecurityCognitive Modeling & Cognitive Systems: Agent Architectures

Application Category

Responsible Web: Machine-in-the-loop, human agency and autonomyUser Modeling, Personalization and Recommendation: Attacks and countermeasures in recommendation systemsSecurity and Privacy: Large-scale security measurements
📝 Abstract
This paper identifies and analyzes a novel vulnerability class in Model Context Protocol (MCP) based agent systems. The attack chain describes and demonstrates how benign, individually authorized tasks can be orchestrated to produce harmful emergent behaviors. Through systematic analysis using the MITRE ATLAS framework, we demonstrate how 95 agents tested with access to multiple services-including browser automation, financial analysis, location tracking, and code deployment-can chain legitimate operations into sophisticated attack sequences that extend beyond the security boundaries of any individual service. These red team exercises survey whether current MCP architectures lack cross-domain security measures necessary to detect or prevent a large category of compositional attacks. We present empirical evidence of specific attack chains that achieve targeted harm through service orchestration, including data exfiltration, financial manipulation, and infrastructure compromise. These findings reveal that the fundamental security assumption of service isolation fails when agents can coordinate actions across multiple domains, creating an exponential attack surface that grows with each additional capability. This research provides a barebones experimental framework that evaluate not whether agents can complete MCP benchmark tasks, but what happens when they complete them too well and optimize across multiple services in ways that violate human expectations and safety constraints. We propose three concrete experimental directions using the existing MCP benchmark suite.
Problem

Research questions and friction points this paper is trying to address.

Identifies vulnerability in MCP agent systems enabling harmful emergent behaviors
Demonstrates how authorized tasks chain into sophisticated cross-domain attack sequences
Reveals service isolation fails when agents coordinate actions across multiple domains
Innovation

Methods, ideas, or system contributions that make the work stand out.

Chaining legitimate operations across multiple services
Using MITRE ATLAS framework for systematic analysis
Testing service orchestration for adversarial attack sequences
🔎 Similar Papers