Skip to main content
在 Manus 中运行任何 Skill
一键导入

detect-prompt-injection-mcp-proxy

星标3
分支0
更新时间2026年7月10日 03:53

Detect suspicious prompt-injection and instruction-smuggling language in MCP tool descriptions from ingest-mcp-proxy-ocsf. Reads OCSF 1.8 Application Activity (class 6002) or the native application-activity projection, keeps a narrow high-signal scope, and flags `tools/list` responses whose tool descriptions explicitly tell an agent to ignore prior instructions, reveal a system or developer prompt, bypass guardrails, or exfiltrate secrets or conversation history. Emits OCSF 1.8 Detection Finding (class 2004) with MITRE ATLAS AML.T0051 Prompt Injection. Use when the user mentions MCP prompt injection, instruction smuggling in tool metadata, malicious tool descriptions, or AI-agent tool poisoning beyond simple schema drift. Do NOT use on raw MCP proxy logs — normalize them through ingest-mcp-proxy-ocsf first. Do NOT use as a general content-moderation classifier or on tool-call results; this slice only covers suspicious tool declarations in `tools/list` responses.

安装

用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。

文件资源管理器
6 个文件
SKILL.md
readonly