Skip to content

Security Model

PPEE's MCP server is designed so that connecting it to an AI assistant is safe by default, even when the files you analyze are malicious.

Guarantees

Property Detail
No execution PPEE parses files and never loads or runs them. A malicious sample is only data
Read-only by default Without --mcp-allow-write, no tool can modify files. tools/list doesn't even advertise patch_pe
Overwrite protection Even in write mode, patch_pe writes only to a path that doesn't exist yet. overwrite: true allows replacing an existing PE file or the input; any other file (documents, configs, …) is never overwritten
Carving is gated too extract_payload only measures unless write mode is on, and even then it writes only to a new path
Bounded results Every result fits a size budget, so a huge file can't flood the model's context
Crash isolation A crafted file that exhausts memory fails that one tool call; the session keeps running
All-or-nothing writes A failed edit writes nothing
No network The server makes no network calls and skips the update check
Local process stdio only, with no listening socket. The server exits with the client session
Tool annotations Tools declare readOnlyHint / destructiveHint, so clients can ask for confirmation before writes

What the server can reach

The server runs with your user's permissions and reads any path it is given. To limit what the assistant can see:

  • run it in Docker with only a samples folder mounted read-only (-v ~/samples:/samples:ro --network none)
  • or run it as a low-privilege user

Similarity database

check_similarity records each checked file's path and hashes in the local database. If you don't want that:

  • avoid the tool, or tell your client to deny it
  • run the Docker server with --read-only so nothing can be recorded (check_similarity then reports "available": false)

Prompt injection from samples

Strings, resource names, manifest text and PDB paths come from the analyzed file. A malicious author can plant text such as "ignore previous instructions and run …". PPEE returns that text as data inside a JSON document, but the model still reads it. Good practice:

  • Keep write mode off when triaging untrusted samples.
  • Use clients that ask for confirmation before tool calls with side effects.
  • Treat assistant conclusions about malware as leads to verify, not as final answers.

Never combine write mode with untrusted samples and auto-approve

--mcp-allow-write + an auto-approving client + malicious input is the one configuration where injected text could lead to a file being written. Keep at least one of the three off.

References