Skip to content

Hide Navigation Hide TOC

MCP Sampling Prompt Injection (Server-to-Client createMessage Abuse) - ATR-2026-01930 (f05d4bd4-f2f4-5136-a65a-c8c7d3df307f)

Detects a malicious or compromised MCP server abusing the MCP sampling capability (sampling/createMessage) to inject attacker-controlled prompts back into the host LLM. Sampling reverses the normal flow: the server, not the user, controls both the prompt and how the completion is processed. An attacker-controlled server appends hidden instructions to an otherwise legitimate request — yielding (1) resource theft (forcing extra unbilled generation), (2) conversation hijacking (persistence injected into every subsequent turn), and (3) covert tool invocation (silent file/exfil operations the user never sees). Detectable artifacts include systemPrompt role-overrides, "after finishing X, also do Y" appendages, "in all future responses" persistence, covert "also invoke the tool to ..." phrasing, and includeContext: thisServer combined with exfiltration to an external URL. New attack class (Unit42 2026); previously 0 ATR coverage for the sampling channel.

Cluster A Galaxy A Cluster B Galaxy B Level
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern MCP Sampling Prompt Injection (Server-to-Client createMessage Abuse) - ATR-2026-01930 (f05d4bd4-f2f4-5136-a65a-c8c7d3df307f) Agent Threat Rules 1
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern MCP Sampling Prompt Injection (Server-to-Client createMessage Abuse) - ATR-2026-01930 (f05d4bd4-f2f4-5136-a65a-c8c7d3df307f) Agent Threat Rules 1
Supply Chain Compromise - T1195 (3f18edba-28f4-4bb9-82c3-8aa60dcac5f7) Attack Pattern MCP Sampling Prompt Injection (Server-to-Client createMessage Abuse) - ATR-2026-01930 (f05d4bd4-f2f4-5136-a65a-c8c7d3df307f) Agent Threat Rules 1
Command and Scripting Interpreter - T1059 (7385dfaf-6886-4229-9ecd-6fd678040830) Attack Pattern MCP Sampling Prompt Injection (Server-to-Client createMessage Abuse) - ATR-2026-01930 (f05d4bd4-f2f4-5136-a65a-c8c7d3df307f) Agent Threat Rules 1
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 2