FEAT: MCP (Model Context Protocol) Integration
Maintainer thường phản hồi trong vòng 2 ngày
Chưa có ai nhận issue này.
Đánh giá
Issue này chưa được đánh giá.
Mô tả
Is your feature request related to a problem? Please describe.
When red teaming agentic AI systems, PyRIT currently requires custom integrations for each external tool, data source, or capability. This creates friction when testing systems that use diverse toolsets and limits the ability to dynamically discover and interact with target capabilities during assessments.
TheModel Context Protocol (MCP) by Anthropic provides a standardized interface for LLM-to-tool communication that's rapidly being adopted across the AI ecosystem. Without MCP support, PyRIT cannot natively interact with MCP-enabled targets or leverage the growing ecosystem of MCP servers for red teaming workflows.
Describe the solution you'd like
Add native MCP support to PyRIT, enabling red teaming agents to dynamically discover and use external tools, data sources, and prompt templates via the MCP protocol.
Core Capabilities:
- Tools: Execute functions (converters, probes, external APIs, target system tools)
- Resources: Read data (attack datasets, MITRE ATLAS mappings, reconnaissance results)
- Prompts: Load templates (red team agent prompts, attack strategies)
Proposed Implementation:
The codebase already defines MCP types in MessagePieceType:
MCP_CALL = "mcp_call"
MCP_LIST_TOOLS = "mcp_list_tools"
MCP_APPROVAL_REQUEST = "mcp_approval_request"
These types aren't implemented yet. This proposal would complete that implementation.
Proposed Usage:
from pyrit.mcp import MCPServerConfig, MCPTransport
# Native MCP support in target
target = OpenAIResponseTarget(
mcp_servers=[
MCPServerConfig(
name="converters",
transport=MCPTransport.STDIO,
command="python",
args=["converters_server.py"]
),
MCPServerConfig(
name="recon",
transport=MCPTransport.SSE,
url="http://localhost:8080/sse"
),
]
)
# Target auto-discovers tools, model can call them during conversation
Implementation Phases:
- Core MCP client implementation using the MCP Python SDK
- Integration with OpenAIResponseTarget
- Integration examples with existing agentic security tools as MCP resources/tool
- Documentation and notebooks
Additional context
Relationship to Existing Issues:
- Supersedes #1083
- Supersedes #1118
References:
Open Questions:
- Should example MCP servers live in PyRIT core or a separate repository?
- Which transport should be prioritized first (STDIO vs SSE)?
- Any security considerations for MCP server sandboxing during red team operations?
I'm happy to start the implementation and can break this into smaller PRs. Would welcome collaboration from anyone interested in this direction.
- Ngôn ngữ chính
- Python
- Star
- 4.5k
- Fork
- 896
- Merge trung bình
- 2 ngày 22 giờ
- Pull request đã merge (30 ngày)
- 220
Chuẩn bị môi trường
Chúng tôi chưa kiểm tra các tệp thiết lập môi trường của dự án này. Hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của microsoft/PyRIT
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
Maintainer thường phản hồi trong vòng 2 ngày
-
Bug: triage GUI help wanted
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
microsoft/PyRIT#2868 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 76/100
Maintainer thường phản hồi trong vòng 2 ngày
Tất cả issue của microsoft/PyRIT
Issue tương tự
-
bug server
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
sportsdataverse/sportsdataverse-py#641 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
googleapis/google-cloud-python#18532 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày