mcp-config-poisoning - Test IDEs for MCP configuration poisoning
Tests whether AI IDEs load untrusted MCP configurations, execute server commands, or allow prompt injection to modify MCP settings.
Tags
Updated: 2026-10-08Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Discover workspace MCP paths
- Test unapproved MCP auto-loading
- Test prompt-driven config modification
- Assess MCP approval controls
- Test trusted-workspace TOCTOU behavior
- Validate observable payload execution
Inputs
- Target IDE
- Workspace MCP config path
- MCP transport mechanism
- IDE version and platform
- Workspace files
- Approval dialogs
Outputs
- MCP poisoning findings
- Observed approval prompts
- Created marker files
- Modified MCP configuration
- Server process launches
- Payload validation results
Requirements
- MCP-capable target IDE
- Known workspace config path
- Identified MCP transport
- Documented IDE version and platform
- Permission to test the IDE
