Agent skill

Hunt MCP

by Encod3d-Sec in Encod3d-Sec/TORCH

MCP server attack hunting - tool poisoning, indirect prompt injection via tool output, rug-pull updates, cross-tool shadowing, over-permissioned/excessive-agency tools, lethal trifecta.

MITAuto-check passedSecurity

Install Hunt MCP

skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill hunt-mcp -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Encod3d-Sec/TORCH hunt-mcp --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt/hunt-mcp .claude/skills/hunt-mcp && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-mcp
GitHub stars
329
Token cost
~1.4k tokens
SKILL.md length
647 words
Files
1
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

MCP server attack hunting - tool poisoning, indirect prompt injection via tool output, rug-pull updates, cross-tool shadowing, over-permissioned/excessive-agency tools, lethal trifecta.

  • Works in 8 steps: Enumerate tools: name, FULL… → Map the trifecta across tools - who… → Tool poisoning: hidden instructions in… → …
  • Tasks that involve Prompt injection and agent security
  • SKILL.md covers Wiki, Attack surface, Methodology and Confirmation gate, plus 4 more sections
  • Calls python3

What it does

Hunt MCP is an agent skill from Encod3d-Sec/TORCH. MCP server attack hunting - tool poisoning, indirect prompt injection via tool output, rug-pull updates, cross-tool shadowing, over-permissioned/excessive-agency tools, lethal trifecta. Wiki-first, FIND schema output.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Prompt injection and agent security and MCP servers. It works with Model Context Protocol. The repository describes itself as: Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian. The licence is MIT.

When your agent uses it

  • Tasks that involve Prompt injection and agent security
  • Tasks that involve MCP servers

Example prompts

  • “/hunt-mcp”

Requirements

  • Python 3

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Enumerate tools: name, FULL description/docstring, parameter schema, permissions. The full
  2. Map the trifecta across tools - who reads secrets, who reads untrusted input, who can reach
  3. Tool poisoning: hidden instructions in the description (often tags) -> read a
  4. Cross-tool shadowing: from one server, hijack a different trusted tool (for example redirect
  5. Indirect injection via tool output: plant instructions in a ticket/web page/file the agent
  6. Rug pull: get a benign tool approved, then mutate its description server-side after approval.
  7. Confirm per the Confirmation gate below - demonstrated execution via the client, never the
  8. Distill when confirmed - reusable poisoning, shadowing, or rug-pull technique, GENERIC, no

What it can do on your machine

Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hunt MCP loads about 1.4k tokens when it runs. Until then it costs about 57 tokens; SKILL.md has 647 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 647 words, ~1,357 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-mcp/SKILL.md (or your agent's skills folder).
name
hunt-mcp
description
MCP server attack hunting - tool poisoning, indirect prompt injection via tool output, rug-pull updates, cross-tool shadowing, over-permissioned/excessive-agency tools, lethal trifecta. Wiki-first, FIND schema output.

Hunt: MCP Server Attacks

Assumes hunt-core for the scope gate, two-account rule, confirmation gate, enumeration limits, stop conditions, wiki protocol, FIND output, and Deadends. Do not re-derive any of that here.

Wiki

qmd_query "MCP server tool poisoning indirect prompt injection rug pull cross-tool shadowing excessive agency lethal trifecta" via wiki-search MCP

Hub: [[web-moc]] (live index). Primary page: [[mcp-server-attacks]]. Anchors: [[llm-attacks]].

Attack surface

Rank before testing. Not all surfaces are equally reachable or impactful:

  • Tool descriptions / docstrings - the FULL text (not the UI summary) is the injection surface. Hidden instructions ride in <IMPORTANT> tags, comments, unicode-tag or zero-width text, and parameter descriptions the client concatenates into the model context.
  • Tool output fed back to the model - any tool that fetches untrusted content (web page, ticket, file, email, issue body) and returns it to the model is an indirect-injection channel. Highest yield because the payload is not in the manifest and survives description review.
  • Over-permissioned / excessive-agency tools - a tool that can write files, send mail, run shell, or hit arbitrary URLs turns any injection into action. The blast radius, not the bug.
  • Lethal trifecta in one agent - private-data access + untrusted input + an outbound/exfil channel. When all three are reachable by a single agent, injection becomes exfil. Map who holds each leg.
  • Exposed MCP infrastructure - MCP servers, tool manifests, agent tool lists, MCP Inspector (CVE-2025-49596, unauth RCE).

Methodology

  1. Enumerate tools: name, FULL description/docstring, parameter schema, permissions. The full description is the attack surface, not the UI summary.
  2. Map the trifecta across tools - who reads secrets, who reads untrusted input, who can reach network/fs. A single agent holding all three legs is the primary target.
  3. Tool poisoning: hidden instructions in the description (often <IMPORTANT> tags) -> read a secret, pass it via a benign-looking param.
  4. Cross-tool shadowing: from one server, hijack a different trusted tool (for example redirect send_email recipients).
  5. Indirect injection via tool output: plant instructions in a ticket/web page/file the agent will read.
  6. Rug pull: get a benign tool approved, then mutate its description server-side after approval.
  7. Confirm per the Confirmation gate below - demonstrated execution via the client, never the model's narration.
  8. Distill when confirmed - reusable poisoning, shadowing, or rug-pull technique, GENERIC, no client host: python3 scripts/wiki-stage.py --kind technique --slug <slug> --target-page techniques/web/mcp-server-attacks.md
Show full SKILL.md (288 more words)Show less

Confirmation gate

NOT confirmation: a tool description that merely contains an injection string; a permissive or over-broad parameter schema; the trifecta being reachable on paper without exercising it across the tools; the model narrating that it "would" or "could" do something; a payload accepted into a description or tool output that the client never acted on.

IS confirmation: the injection actually executed via the client - a shadowed or poisoned tool invoked with attacker-chosen arguments, private data exfiltrated to your endpoint, or an unintended action taken by the agent - reproduced in a clean session. For rug-pull, the mutation took effect on an already-approved tool and the client acted on the new description.

Chaining

Tool-output injection (step 5) -> excessive agency: once you control the model's instructions via poisoned output, the impact is whatever the over-permissioned tools can do (mail, files, shell, outbound HTTP). That escalation is prompt-injection territory - hand off to hunt-llm for the injection-to-action payload work, keep the MCP-specific poisoning/shadowing here.

Evasion

Description review and human approval are the controls to bypass. Hide instructions where a reviewer skims past: <IMPORTANT>/comment blocks, zero-width or unicode-tag characters, whitespace padding, instructions split across several tools' descriptions, and payloads in parameter descriptions rather than the top-level docstring. Against approval flows, the rug-pull is the evasion: ship benign, mutate after the human clicks approve.

Severity

Rated on demonstrated impact, not the presence of a payload.

OutcomeTypical
RCE on the MCP host or client (e.g. MCP Inspector CVE-2025-49596)critical
Secret / credential exfil via poisoned or shadowed toolcritical
Cross-tool hijack - arbitrary attacker-controlled tool actionhigh
Data exfil - private context reaching an attacker channelhigh
Over-permissioned tool, limited demonstrable impactmedium

Deadends

Append: - [ ] MCP attack on <server> -- no client-side execution; descriptions clean,
              no reachable trifecta, tool output not acted on

Record what you tried (poisoning / shadowing / indirect-output / rug-pull), not just that it failed.

© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hunt/hunt-mcp of Encod3d-Sec/TORCH.

Open the folder on GitHubat commit d21b6c9

Compare with similar skills

Hunt MCP next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunt MCP compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunt MCP this skillEncod3d-Sec/TORCH329—~1.4kAutomated safety check: PassMIT
Forensifyalexgreensh/repo-forensics190—~2.5kAutomated safety check: NotesCustom licence
Hol Guardhashgraph-online/hol-guard845—~542Automated safety check: PassApache-2.0
Plugin Scanneriflytek/skillhub5.2k2 repos~1.1kAutomated safety check: NotesApache-2.0
MCP Server Security Auditawarexone/Agentic-Bug-Hunter5.3k—~1.9kAutomated safety check: WarnMIT
Securing AI Systemstrilwu/secskills157—~2.9kAutomated safety check: PassMIT

Similar skills

  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    190 GitHub stars~2.5k tokensUpdated 13 days ago
    SecurityAuto-check: notes
  • Hol Guard

    hashgraph-online/hol-guard

    Run HOL Guard scanner and guard operations via uv run hol-guard.

    845 GitHub stars~542 tokensUpdated today
    SecurityAuto-check passed
  • Plugin Scanner

    iflytek/skillhub

    Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.

    5.2k GitHub starsUsed in 2 repos~1.1k tokens
    SecurityAuto-check: notes
  • MCP Server Security Audit

    awarexone/Agentic-Bug-Hunter

    Audits MCP servers and their client configs for tool poisoning, prompt injection, over-privileged tools, injection bugs, secret leaks and missing approval gates.

    5.3k GitHub stars~1.9k tokensUpdated yesterday
    SecurityAuto-check: warnings
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Auditing MCP Servers For Tool Poisoning

    mukul975/Anthropic-Cybersecurity-Skills

    Audit MCP servers for tool poisoning, tool shadowing, rug pulls, SSRF, and unauthenticated exposure using Invariant Labs' mcp-scan for static/runtime scanning plus manual SSRF/auth checks and…

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    SecurityAuto-check: warnings

More from Encod3d-Sec/TORCH

All 35 skills in this repo
  • Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.

    329 GitHub stars~611 tokensUpdated 1 mo ago
    Auto-check passed
  • Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

    329 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • CTF Campaign Driver

    Encod3d-Sec/TORCH

    Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.

    329 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check: notes
  • Adaptive Web Fuzzing

    Encod3d-Sec/TORCH

    Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

    329 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Hunt MCP

What does Hunt MCP do?

MCP server attack hunting - tool poisoning, indirect prompt injection via tool output, rug-pull updates, cross-tool shadowing, over-permissioned/excessive-agency tools, lethal trifecta. Hunt MCP is an agent skill from Encod3d-Sec/TORCH. MCP server attack hunting - tool poisoning, indirect prompt injection via tool output, rug-pull updates, cross-tool shadowing, over-permissioned/excessive-agency tools, lethal trifecta.

When should I use Hunt MCP?

Hunt MCP fits situations like: tasks that involve Prompt injection and agent security; tasks that involve MCP servers.

How do I install Hunt MCP in Claude Code?

Run `npx skills add Encod3d-Sec/TORCH --skill hunt-mcp -a claude-code`. Or copy the skill folder (skills/hunt/hunt-mcp in Encod3d-Sec/TORCH) into .claude/skills/hunt-mcp in your project. Claude Code loads it when a task matches its description.

How do I install Hunt MCP in Codex?

Run `npx skills add Encod3d-Sec/TORCH --skill hunt-mcp -a codex`. Or copy the skill folder (skills/hunt/hunt-mcp in Encod3d-Sec/TORCH) into .agents/skills/hunt-mcp in your project. Codex loads it when a task matches its description.

Can I use Hunt MCP in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill hunt-mcp -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-mcp, .gemini/skills/hunt-mcp, .github/skills/hunt-mcp and .opencode/skills/hunt-mcp in your project.

What does Hunt MCP need to run?

Going by SKILL.md and its folder, Hunt MCP needs the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Hunt MCP access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hunt MCP safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hunt MCP use?

Hunt MCP is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunt MCP use?

About 1.4k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hunt MCP?

Skills that share tags, products or a category with Hunt MCP: Forensify (alexgreensh/repo-forensics, 190 stars), Hol Guard (hashgraph-online/hol-guard, 845 stars), Plugin Scanner (iflytek/skillhub, 5.2k stars) and MCP Server Security Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunt MCP?

Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.

Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.