MCP Servers & Tools
Model Context Protocol servers look like ordinary backends from the outside, but the agent — not a human — decides which tool to call and with what arguments. That changes what needs testing.
What can go wrong
Tool-selection abuse
An attacker convinces the calling agent to invoke a destructive tool it technically has permission to call, just not for that purpose.
Over-broad tool scopes
A tool inherits the whole backend service's credentials because scoping it individually was extra work.
Cross-tool data leakage
Data pulled by one tool call becomes context for the next — including tools that were never meant to see it.
Confused-deputy chains
Legitimate, individually-authorized tool calls combine into an action no single call should have been able to perform.
Illustrative attack path
This is a representative validation target, not a claim that every customer system exposes the same chain.
What Oxyne tests
How it works
Point Oxyne at the MCP server's endpoint. It enumerates the exposed tool set, maps each tool's real scope, and runs adversarial sessions designed to trigger tool-selection abuse and cross-tool leakage — the failure modes a tool-by-tool schema audit misses.
Scoped interface
Define supported connection paths, authorized actions, credentials, and prohibited behavior before testing.
Evidence produced
Receive the supporting transcript, explicit success criteria, judge reasoning, validation level, and remediation context.
Applicable workflows
Use recurring AI Security Testing for baseline coverage and a separately scoped AI Red Teaming campaign for deeper analysis.
See Oxyne on your own systems.
Book a 30-minute walkthrough — we'll scope a real assessment for your AI and web surfaces.