hackwither_

reap / rules / recon: capability surface

MCP handshake returns lengthy or sensitive-flavored instructions

mcp-instructions-exposure ASI09 Human-Agent Trust Exploitation severity: low

What it detects

Handshake instructions field leaking operator prompt material (long text or secrecy/credential-flavored keywords). ASI09.

Flags the initialize response's free-text instructions field when it's long (>400 chars) or contains secrecy/credential-flavored keywords ("never reveal", "api key", "internal", ...).

applies to MCP endpoints

Why it matters

Operator prompt material returned pre-authentication is unintended disclosure through a protocol field.

OWASP ASI mapping rationale

Example finding

LOW  mcp-instructions-exposure  MEDIUM CONFIDENCE
MCP handshake returns lengthy or sensitive-flavored instructions
The initialize response's 'instructions' field is long and/or contains language patterns (secrecy directives, 'internal', credential-related terms) worth a human review to confirm it isn't leaking operational or internal detail to any caller.
Evidence  POST /mcp → 200

from a scan of reap-range, bad target

Fix

Keep client-facing instructions limited to usage guidance; keep anything sensitive out of fields returned pre-authentication.

On reap-range

insecure targetbad/mcp (long, "never reveal"/"internal"/"api key") · Low
correct targetgood/mcp instructions are short & generic

Run only this check

reap -t https://your-host/mcp --authorized --include mcp-instructions-exposure

Not installed? Install REAP. Only scan systems you own or are authorised to test. Reference: docs/PROBES.md.