Skip to content

Python: Model MCP and FastMCP server handler parameters as remote sources (#22702) - #22750

Open
Tito0015 wants to merge 2 commits into
github:mainfrom
Tito0015:feature/python-mcp-remote-sources
Open

Tito0015 wants to merge 2 commits into
github:mainfrom
Tito0015:feature/python-mcp-remote-sources

Conversation

@Tito0015

@Tito0015 Tito0015 commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Summary

Fixes #22702.

This PR adds QL framework modeling for Python MCP (Model Context Protocol) and fastmcp server handler parameters as RemoteFlowSources.

Why QL Modeling instead of Models-as-Data (YAML)

Existing open PR #22703 models MCP via Models-as-Data (MaD) YAML (ThreatModelSource of kind remote). However, several legacy Python security queries (such as py/nosql-injection, py/xml-bomb, and py/xxe) query RemoteFlowSource::Range directly and do not consume MaD sources. Additionally, MaD currently misses tool handlers wrapped behind stacked custom decorators.

Modeling via Mcp.qll extending RemoteFlowSource::Range resolves both gaps natively.

What is Modeled

  • @mcp.tool(), @mcp.prompt(), @mcp.resource() (called and bare forms) across FastMCP and MCPServer (MCP 2.x).
  • Standalone fastmcp @tool, @prompt, @resource, and fastmcp.tools.tool.
  • Function registration via add_tool(...).
  • def and async def functions, methods registered via @self.mcp.tool(), and stacked decorators (@other above @mcp.tool()).

Exclusions

  • Method receivers (self / cls).
  • Parameters type-annotated as Context (or Context | None / Optional[Context]).

Testing

  • Added unit tests under python/ql/test/library-tests/dataflow/remote-flow-sources/ covering sync/async, bare/called decorators, keyword-only args, stacked decorators, and negative exclusion cases.
  • All tests pass locally via codeql test run.

@Tito0015
Tito0015 requested review from a team as code owners October 4, 2026 05:43
Alex-Hofer added a commit to Alex-Hofer/mcp-vulnbench that referenced this pull request Oct 4, 2026


Both proposals for Python MCP sources on the 28 Python cases: the class detects 9, the rows 13, both 13. Records what each covers that the other does not, the method (derived image, checks) and the limits of the comparison.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Python: model MCP server handler parameters (mcp, fastmcp) as remote sources

1 participant