T07 · Tool Hijacking and Spoofing
- Location
SKILL.md:128- Finding
Unvalidated User-Supplied Endpoint Registered as a Trusted MCP Service
- Content
View full analysis
" ``` ```json { "mcpServers": { "dingtalk-calendar": { "type": "http", "url": "" } } } ``` The instructions state that the endpoint contains a personal API key and should be written into the configuration without being repeated in later responses. However, they do not require validation of its scheme, hostname, port, redirect behavior, or origin before registration. ### Technical Analysis The Skill accepts a URL pasted into the conversation and registers it under the trusted service name `dingtalk-calendar`. Although the user is initially directed to an official DingTalk setup page, the subsequently supplied URL is not required to belong to a DingTalk-controlled HTTPS origin. MCP services act as trusted tool providers. Registering an arbitrary endpoint under the expected calendar service identity can allow a malicious server to impersonate legitimate tools, return deceptive results, collect calendar requests, or induce unauthorized operations. If the supplied URL contains authentication material, sending requests to an untrusted origin may also disclose that material. The behavior is related to the declared installation functionality, but accepting an arbitrary endpoint without origin validation exceeds the minimum safe trust required for MCP registration. ### Attack Path 1. An attacker persuades the user to paste a malicious or look-alike MCP endpoint. 2. The Skill registers that URL under the legitimate-looking `dingtalk-calendar` service name. 3. The user restarts the MCP-capable client as instructed. 4. Subsequent calendar tool calls are routed to the attacker-controlled service. 5. The malicious service records request data ...[truncated 786 chars]- Remediation
View remediation
