Security Model¶
PPEE's MCP server is designed so that connecting it to an AI assistant is safe by default, even when the files you analyze are malicious.
Guarantees¶
| Property | Detail |
|---|---|
| No execution | PPEE parses files and never loads or runs them. A malicious sample is only data |
| Read-only by default | Without --mcp-allow-write, no tool can modify files. tools/list doesn't even advertise patch_pe |
| Overwrite protection | Even in write mode, patch_pe writes only to a path that doesn't exist yet. overwrite: true allows replacing an existing PE file or the input; any other file (documents, configs, …) is never overwritten |
| Carving is gated too | extract_payload only measures unless write mode is on, and even then it writes only to a new path |
| Bounded results | Every result fits a size budget, so a huge file can't flood the model's context |
| Crash isolation | A crafted file that exhausts memory fails that one tool call; the session keeps running |
| All-or-nothing writes | A failed edit writes nothing |
| No network | The server makes no network calls and skips the update check |
| Local process | stdio only, with no listening socket. The server exits with the client session |
| Tool annotations | Tools declare readOnlyHint / destructiveHint, so clients can ask for confirmation before writes |
What the server can reach¶
The server runs with your user's permissions and reads any path it is given. To limit what the assistant can see:
- run it in Docker with only a samples folder mounted read-only (
-v ~/samples:/samples:ro --network none) - or run it as a low-privilege user
Similarity database¶
check_similarity records each checked file's path and hashes in the local database. If you don't want that:
- avoid the tool, or tell your client to deny it
- run the Docker server with
--read-onlyso nothing can be recorded (check_similaritythen reports"available": false)
Prompt injection from samples¶
Strings, resource names, manifest text and PDB paths come from the analyzed file. A malicious author can plant text such as "ignore previous instructions and run …". PPEE returns that text as data inside a JSON document, but the model still reads it. Good practice:
- Keep write mode off when triaging untrusted samples.
- Use clients that ask for confirmation before tool calls with side effects.
- Treat assistant conclusions about malware as leads to verify, not as final answers.
Never combine write mode with untrusted samples and auto-approve
--mcp-allow-write + an auto-approving client + malicious input is the one configuration where injected text could lead to a file being written. Keep at least one of the three off.
References¶
- Model Context Protocol specification: the protocol PPEE's MCP server implements.