Skip to content
Search
paperApril 2026Unreviewed

Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models

Yannis Belkhiter, Giulio Zizzo, Sergio Maffeis, Seshu Tirupathi, John D. Kelleher

Abstract

The growth of agentic AI has drawn significant attention to function calling Large Language Models (LLMs), which are designed to extend the capabilities of AI-powered system by invoking external functions. Injection and jailbreaking attacks have been extensively explored to showcase the vulnerabilities of LLMs to user prompt manipulation. The expanded capabilities of agentic models introduce further vulnerabilities via their function calling interface. Recent work in LLM security showed that fun

Categories

Framework mappings

OWASP Top 10 for Agentic Applications
  • ASI02Tool Misuse & Exploitation
MITRE ATLAS
  • AML.T0053AI Agent Tool Invocation
  • AML.T0054LLM Jailbreak

Suggested from the entry's categories.

Cite

@misc{belkhiter2026breaking,
  title = {{Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models}},
  author = {Yannis Belkhiter and Giulio Zizzo and Sergio Maffeis and Seshu Tirupathi and John D. Kelleher},
  year = {2026},
  month = apr,
  eprint = {2604.20994},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2604.20994}
}