Skip to content
Search
paperSeptember 2026Unreviewed

No-Box Vulnerability Analysis: Description-only Detection of Indirect Prompt Injection Vulnerabilities in MCP Servers

Zehua Zhang, Jie Hu, Pratham Hegde, Aditya Maheshbhai Gabani, Souradip Nath, Yibo Liu, Siyu Liu, Hongkai Chen, Hulin Wang, Zhuoer Lyu, Chang Zhu, Divij Handa, Yan Shoshitaishvili, Tiffany Bao, Ruoyu Wang, Adam Doupe

Abstract

Conventional vulnerability analysis relies on either system access or dynamic interaction, all of which may be unavailable to third-party analysts auditing closed-source, remotely hosted, critical in situ systems, or commercially gated software. Therefore, we propose a new paradigm of no-box vulnerability analysis in which neither access nor runtime interaction is available, and only functionality metadata is available. Such metadata defines the intended behavior of the system, including its inp

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{zhang2026nobox,
  title = {{No-Box Vulnerability Analysis: Description-only Detection of Indirect Prompt Injection Vulnerabilities in MCP Servers}},
  author = {Zehua Zhang and Jie Hu and Pratham Hegde and Aditya Maheshbhai Gabani and Souradip Nath and Yibo Liu and Siyu Liu and Hongkai Chen and Hulin Wang and Zhuoer Lyu and Chang Zhu and Divij Handa and Yan Shoshitaishvili and Tiffany Bao and Ruoyu Wang and Adam Doupe},
  year = {2026},
  month = sep,
  eprint = {2609.10854},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2609.10854}
}