> ## Documentation Index
> Fetch the complete documentation index at: https://docs.switchagents.ai/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> These docs moved from docs.flintai.dev to docs.switchagents.ai. Use docs.switchagents.ai for every link and request.
> To search these docs from an AI tool, connect the MCP server at https://docs.switchagents.ai/mcp. The page index is at https://docs.switchagents.ai/llms.txt.

# MCP server rules

> Vulnerabilities in MCP servers, tools, and their configurations

MCP server rules cover vulnerabilities in MCP servers, tools, and their configurations.

* [Code injection](/switch-trust/rules/code-injection)
* [Command injection](/switch-trust/rules/command-injection)
* [Confused deputy attack](/switch-trust/rules/confused-deputy-attack)
* [Context overexposure/leakage](/switch-trust/rules/context-overexposure)
* [Context spoofing/integrity violation](/switch-trust/rules/context-spoofing)
* [Cross-server tool shadowing/interference](/switch-trust/rules/cross-server-tool-shadowing)
* [Data exfiltration via legitimate tools](/switch-trust/rules/data-exfiltration)
* [Dynamic behavior change (rug pull)](/switch-trust/rules/rug-pull)
* [Excessive permissions (least privilege violation)](/switch-trust/rules/excessive-permissions)
* [Exposed unnecessary ports/interfaces](/switch-trust/rules/exposed-ports)
* [Hardcoded credentials](/switch-trust/rules/hardcoded-credentials)
* [Indirect prompt injection](/switch-trust/rules/indirect-prompt-injection)
* [Insecure direct object references (IDOR)](/switch-trust/rules/insecure-direct-object-references)
* [Insecure memory/context persistence](/switch-trust/rules/insecure-memory-context-persistence)
* [Insufficient authorization/access control](/switch-trust/rules/insufficient-authorization)
* [Lack of observability & auditing](/switch-trust/rules/lack-of-observability)
* [Lack of transport encryption (TLS)](/switch-trust/rules/lack-of-tls)
* [Missing/weak authentication](/switch-trust/rules/missing-weak-authentication)
* [Model/tool identity misbinding](/switch-trust/rules/model-tool-identity-misbinding)
* [Path traversal](/switch-trust/rules/path-traversal)
* [Resource exhaustion](/switch-trust/rules/resource-exhaustion)
* [Sampling vulnerability](/switch-trust/rules/sampling-vulnerability)
* [Shadow/unmanaged MCP servers](/switch-trust/rules/shadow-unmanaged-mcp-servers)
* [Silent redefinition](/switch-trust/rules/silent-redefinition)
* [Supply chain risks/dependency tampering](/switch-trust/rules/dependency-tampering)
* [Tool poisoning (malicious instructions in metadata)](/switch-trust/rules/tool-poisoning)
* [Untrusted third-party MCP servers](/switch-trust/rules/untrusted-third-party-mcp-servers)
