No-Box Vulnerability Analysis: Description-only Detection of Indirect Prompt Injection Vulnerabilities in MCP Servers
Zehua Zhang, Jie Hu, Pratham Hegde, Aditya Maheshbhai Gabani, Souradip Nath, Yibo Liu, Siyu Liu, Hongkai Chen, Hulin Wang, Zhuoer Lyu, Chang Zhu, Divij Handa, Yan Shoshitaishvili, Tiffany Bao, Ruoyu Wang, Adam Doupe
Abstract
Conventional vulnerability analysis relies on either system access or dynamic interaction, all of which may be unavailable to third-party analysts auditing closed-source, remotely hosted, critical in situ systems, or commercially gated software. Therefore, we propose a new paradigm of no-box vulnerability analysis in which neither access nor runtime interaction is available, and only functionality metadata is available. Such metadata defines the intended behavior of the system, including its inp
Categories
Framework mappings
- LLM01Prompt Injection
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{zhang2026nobox,
title = {{No-Box Vulnerability Analysis: Description-only Detection of Indirect Prompt Injection Vulnerabilities in MCP Servers}},
author = {Zehua Zhang and Jie Hu and Pratham Hegde and Aditya Maheshbhai Gabani and Souradip Nath and Yibo Liu and Siyu Liu and Hongkai Chen and Hulin Wang and Zhuoer Lyu and Chang Zhu and Divij Handa and Yan Shoshitaishvili and Tiffany Bao and Ruoyu Wang and Adam Doupe},
year = {2026},
month = sep,
eprint = {2609.10854},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2609.10854}
}