reap / rules / recon: capability surface
MCP handshake returns lengthy or sensitive-flavored instructions
mcp-instructions-exposure ASI09 Human-Agent Trust Exploitation severity: low
What it detects
Handshake instructions field leaking operator prompt material (long text or secrecy/credential-flavored keywords). ASI09.
Flags the initialize response's free-text instructions field when it's long (>400 chars) or contains secrecy/credential-flavored keywords ("never reveal", "api key", "internal", ...).
applies to MCP endpoints
Why it matters
Operator prompt material returned pre-authentication is unintended disclosure through a protocol field.
Example finding
LOW mcp-instructions-exposure MEDIUM CONFIDENCE MCP handshake returns lengthy or sensitive-flavored instructions The initialize response's 'instructions' field is long and/or contains language patterns (secrecy directives, 'internal', credential-related terms) worth a human review to confirm it isn't leaking operational or internal detail to any caller. Evidence POST /mcp → 200
from a scan of reap-range, bad target
Fix
Keep client-facing instructions limited to usage guidance; keep anything sensitive out of fields returned pre-authentication.
On reap-range
| insecure target | bad/mcp (long, "never reveal"/"internal"/"api key") · Low |
| correct target | good/mcp instructions are short & generic |
Run only this check
reap -t https://your-host/mcp --authorized --include mcp-instructions-exposure
Not installed? Install REAP. Only scan systems you own or are authorised to test. Reference: docs/PROBES.md.