SMCP: Secure Model Context Protocol

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Hou, Xinyi, Wang, Shenao, Zhang, Yifan, Xue, Ziluo, Zhao, Yanjie, Fu, Cai, Wang, Haoyu
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911413921906688
author Hou, Xinyi
Wang, Shenao
Zhang, Yifan
Xue, Ziluo
Zhao, Yanjie
Fu, Cai
Wang, Haoyu
author_facet Hou, Xinyi
Wang, Shenao
Zhang, Yifan
Xue, Ziluo
Zhao, Yanjie
Fu, Cai
Wang, Haoyu
contents Agentic AI systems built around large language models (LLMs) are moving away from closed, single-model frameworks and toward open ecosystems that connect a variety of agents, external tools, and resources. The Model Context Protocol (MCP) has emerged as a standard to unify tool access, allowing agents to discover, invoke, and coordinate with tools more flexibly. However, as MCP becomes more widely adopted, it also brings a new set of security and privacy challenges. These include risks such as unauthorized access, tool poisoning, prompt injection, privilege escalation, and supply chain attacks, any of which can impact different parts of the protocol workflow. While recent research has examined possible attack surfaces and suggested targeted countermeasures, there is still a lack of systematic, protocol-level security improvements for MCP. To address this, we introduce the Secure Model Context Protocol (SMCP), which builds on MCP by adding unified identity management, robust mutual authentication, ongoing security context propagation, fine-grained policy enforcement, and comprehensive audit logging. In this paper, we present the main components of SMCP, explain how it helps reduce security risks, and illustrate its application with practical examples. We hope that this work will contribute to the development of agentic systems that are not only powerful and adaptable, but also secure and dependable.
format Preprint
id arxiv_https___arxiv_org_abs_2602_01129
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle SMCP: Secure Model Context Protocol
Hou, Xinyi
Wang, Shenao
Zhang, Yifan
Xue, Ziluo
Zhao, Yanjie
Fu, Cai
Wang, Haoyu
Cryptography and Security
Agentic AI systems built around large language models (LLMs) are moving away from closed, single-model frameworks and toward open ecosystems that connect a variety of agents, external tools, and resources. The Model Context Protocol (MCP) has emerged as a standard to unify tool access, allowing agents to discover, invoke, and coordinate with tools more flexibly. However, as MCP becomes more widely adopted, it also brings a new set of security and privacy challenges. These include risks such as unauthorized access, tool poisoning, prompt injection, privilege escalation, and supply chain attacks, any of which can impact different parts of the protocol workflow. While recent research has examined possible attack surfaces and suggested targeted countermeasures, there is still a lack of systematic, protocol-level security improvements for MCP. To address this, we introduce the Secure Model Context Protocol (SMCP), which builds on MCP by adding unified identity management, robust mutual authentication, ongoing security context propagation, fine-grained policy enforcement, and comprehensive audit logging. In this paper, we present the main components of SMCP, explain how it helps reduce security risks, and illustrate its application with practical examples. We hope that this work will contribute to the development of agentic systems that are not only powerful and adaptable, but also secure and dependable.
title SMCP: Secure Model Context Protocol
topic Cryptography and Security
url https://arxiv.org/abs/2602.01129