Workflow

MCP Trust Boundary Suite

Inventory HoneyMCP ghost tools and MCParasite channels, then correlate MCP trust-boundary findings you can retest.

100%

Notes on this workflow

How It Works

Lists ghost tools the catalog would expose, and worm-style channels between MCP servers.

Results

Ghost tools, channels, and report.json.

Target

Your HoneyMCP config. Replace the demo seed, or mount your honeymcp.yaml.

Overview

MCP servers widen what an agent can touch. Ghost tools, miswired channels, and scenario inventories need a smoke path that does not require SaaS tokens, plus a place to drop your own HoneyMCP config when you harden a real stack.

This is a standing check for continuous security testing. You seed a demo HoneyMCP config, run HoneyMCP for a ghost-tool catalog and MCParasite for channel or scenario inventory, then correlate findings with a retest delta when MCP configs change.

It sits next to Web AI Agent Audit (embedded web agents). This Collection unit is the MCP trust-boundary path: config and channel inventory first. Set MCParasite mode=run and LLM keys when you want a live kill-chain.

Pipeline

  1. Seed · Demo HoneyMCP config emits a fixture honeymcp.yaml for the smoke path.
  2. Scan · HoneyMCP ghost catalog reads that config and lists ghost or unexpected tools.
  3. Scan · MCParasite channels inventories channels or scenarios (list mode by default).
  4. Results · Correlate merges both folders into findings, inventory, remediation, and retest_delta outputs.

Inputs

  • Seed HoneyMCP config. Default demo YAML. Replace with your honeymcp.yaml.
  • MCParasite mode. Default list/inventory. run needs LLM keys in vault (chips already wired) and executes a live kill-chain.

Outputs

  • findings.jsonl. MCP trust-boundary hits with remediation hints.
  • inventory.jsonl. Tools and channels observed.
  • retest_delta.jsonl. Schedule-as-diff scaffold when MCP configs change.

Integrations

Sample output

Sample shape from the correlate pack on the demo config (illustrative, not a live KPI).

kindtitleseveritynote
findingGhost or unexpected MCP tool exposurehighnull
inventorynullnullMCP channel or scenario row from the list pass
retest_deltanullnullSchedule re-runs when honeymcp.yaml or channel wiring changes

FAQ

Do I need SaaS tokens for the smoke?

No. The default seed and list modes run without SaaS credentials.

When do I enable MCParasite run mode?

Set mode=run on MCParasite and add OpenAI or Anthropic keys in vault (already wired on the node). Default list stays on inventory.

Why schedule this?

Correlate emits retest_delta.jsonl so scheduled re-runs can surface MCP config drift after agent and server changes.

Get a personalized demo

See Trickest in Action

A 30-minute walkthrough. We map the platform to your stack and answer pricing and deployment questions for your environment.