Manage Interactions - Prompt Attack
Overview
Global Prompt Attack Detection analyzes MCP (Model Context Protocol) tool definitions and MCP tool calls for prompt-attack indicators.
When enabled, Workforce AI Security analyzes:
-
MCP tool definitions (tool names and descriptions)
-
MCP tool call inputs
-
MCP tool call outputs
The analysis generates detection events which are recorded on the Events page. During Early Availability, the feature operates in Detect mode only and does not block, modify, or sanitize traffic.
Early Availability
Prompt Attack Detection is available only to tenants enrolled in the Early Availability (EA) program.
If Prompt Attack does not appear in the portal, the account is not enrolled in the Early Availability program. Contact Check Point Support or your Check Point account team to request enrollment.
During Early Availability:
-
The feature operates in Detect mode only.
-
Traffic is not blocked or modified.
-
Configuration is global and applies to all users, devices, and MCP servers.
-
Per-rule scoping is not available.
-
Detection events do not include policy attribution.
Detection Mode
When you enable Prompt Attack Detection, Workforce AI Security starts monitoring MCP-related traffic and analyzing selected content using configured detectors.
-
Tool definitions. When an MCP server loads and returns its tools list, every tool definition (name and description) is analyzed. Tool definitions are analyzed when an MCP server returns its tools list.
-
Tool calls. When an agent calls an MCP tool, both the input sent to the tool and the output returned by it are analyzed. If both the input and output of the same tool call trigger detections, separate detection records are created for each.
Detection analysis is performed asynchronously and does not delay MCP tool execution.
Tool calls are not held while a detection verdict is being generated. Users experience no additional latency due to the analysis process.
Sensitivity Levels
Each detector can be configured with one of four sensitivity levels.
|
Level |
Name |
Behavior |
|---|---|---|
|
L1 |
Confident Only |
Generates detections only for high-confidence matches. |
|
L2 |
Balanced |
Provides balanced detection coverage. |
|
L3 |
Sensitive |
Generates broader detection coverage and potentially more false positives. |
|
L4 |
Maximum Coverage |
Generates the highest detection volume and the highest likelihood of false positives. |
Prerequisites
Before enabling Global Prompt Attack Detection, ensure that:
-
The account is enrolled in the Early Availability program.
-
Workforce AI Security is deployed in the environment.
-
Endpoints are running a supported agent version.
-
You have administrator permissions in the portal.
Enabling Prompt Attack detection
To enable Prompt Attack detection:
-
From the left menu, select Workforce AI > Manage Interactions > Prompt Attack.
-
Click the toggle button below Apply to all agentic traffic.
-
Verify that the operating mode is Detect.
-
Configure the desired sensitivity level (L1-L4) for each detector.
-
Click Save Changes.
Detection begins after endpoints receive the updated policy.
To review detection activity:
-
From the left menu, select Workforce AI > Events.
-
Open the Agentic tab.
-
Apply the Action: Detect filter or click the Detections only button above the table.
-
Open an event to view its details. Under Detection Detail, see this information:
-
Detection ID
-
Detection source - tool call input or tool description
-
Triggered detectors and detection level
-
Analyzed payload information
For tool definition detections, the event displays the tool name and description that were analyzed. For tool call detections, the event displays the associated input or output content.
-
To provide detection feedback:
-
Open a detection event.
-
Navigate to Detection Details.
-
In the section Is this detection accurate?, select:
-
Thumbs Up to confirm the detection.
-
Thumbs Down to mark the detection as a false positive.
-
-
Optionally provide a reason for the feedback.
-
Use Undo to change the recorded verdict.
Feedback is stored with the detection record.
Limitations
During Early Availability:
-
Detect mode is the only supported operating mode.
-
Traffic cannot be blocked, sanitized, or modified.
-
Configuration is global and cannot be scoped by rule, user, device, or MCP server.
-
Detection logs do not contain policy attribution information.
-
Analysis is limited to MCP tool definitions and MCP tool calls.
-
High sensitivity levels can generate large numbers of detection events.