Prompts Don't Protect: Architectural Enforcement via MCP Proxy for LLM Tool Access Control
Fuente:
arXiv
Saved in:
| Main Author: | Uppala, Rohith |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Don't believe everything you read: Understanding and Measuring MCP Behavior under Misleading Tool Descriptions
by: Li, Zhihao, et al.
Published: (2026)
by: Li, Zhihao, et al.
Published: (2026)
MCP Bridge: A Lightweight, LLM-Agnostic RESTful Proxy for Model Context Protocol Servers
by: Ahmadi, Arash, et al.
Published: (2025)
by: Ahmadi, Arash, et al.
Published: (2025)
MCP-ITP: An Automated Framework for Implicit Tool Poisoning in MCP
by: Li, Ruiqi, et al.
Published: (2026)
by: Li, Ruiqi, et al.
Published: (2026)
Secure Tool Manifest and Digital Signing Solution for Verifiable MCP and LLM Pipelines
by: Jamshidi, Saeid, et al.
Published: (2026)
by: Jamshidi, Saeid, et al.
Published: (2026)
CASCADE: A Cascaded Hybrid Defense Architecture for Prompt Injection Detection in MCP-Based Systems
by: Turgut, İpek Abasıkeleş, et al.
Published: (2026)
by: Turgut, İpek Abasıkeleş, et al.
Published: (2026)
Structural Enforcement of Goal Integrity in AI Agents via Separation-of-Powers Architecture
by: Xiang, Rong
Published: (2026)
by: Xiang, Rong
Published: (2026)
Don't Click That: Teaching Web Agents to Resist Deceptive Interfaces
by: Zhang, Yilin, et al.
Published: (2026)
by: Zhang, Yilin, et al.
Published: (2026)
Please Don't Kill My Vibe: Empowering Agents with Data Flow Control
by: Summers, Charlie, et al.
Published: (2025)
by: Summers, Charlie, et al.
Published: (2025)
To Protect the LLM Agent Against the Prompt Injection Attack with Polymorphic Prompt
by: Wang, Zhilong, et al.
Published: (2025)
by: Wang, Zhilong, et al.
Published: (2025)
Fast Proxies for LLM Robustness Evaluation
by: Beyer, Tim, et al.
Published: (2025)
by: Beyer, Tim, et al.
Published: (2025)
ETDI: Mitigating Tool Squatting and Rug Pull Attacks in Model Context Protocol (MCP) by using OAuth-Enhanced Tool Definitions and Policy-Based Access Control
by: Bhatt, Manish, et al.
Published: (2025)
by: Bhatt, Manish, et al.
Published: (2025)
From Tool Orchestration to Code Execution: A Study of MCP Design Choices
by: Felendler, Yuval, et al.
Published: (2026)
by: Felendler, Yuval, et al.
Published: (2026)
MemLineage: Lineage-Guided Enforcement for LLM Agent Memory
by: Ouyang, Ciyan, et al.
Published: (2026)
by: Ouyang, Ciyan, et al.
Published: (2026)
Bypassing AI Control Protocols via Agent-as-a-Proxy Attacks
by: Isbarov, Jafar, et al.
Published: (2026)
by: Isbarov, Jafar, et al.
Published: (2026)
Tailored Prompts, Targeted Protection: Vulnerability-Specific LLM Analysis for Smart Contracts
by: Zhang, Xing, et al.
Published: (2026)
by: Zhang, Xing, et al.
Published: (2026)
Trivial Trojans: How Minimal MCP Servers Enable Cross-Tool Exfiltration of Sensitive Data
by: Croce, Nicola, et al.
Published: (2025)
by: Croce, Nicola, et al.
Published: (2025)
MCP-in-SoS: Risk assessment framework for open-source MCP servers
by: Kumar, Pratyay, et al.
Published: (2026)
by: Kumar, Pratyay, et al.
Published: (2026)
LLM Cyber Evaluations Don't Capture Real-World Risk
by: Lukošiūtė, Kamilė, et al.
Published: (2025)
by: Lukošiūtė, Kamilė, et al.
Published: (2025)
MCP Guardian: A Security-First Layer for Safeguarding MCP-Based AI System
by: Kumar, Sonu, et al.
Published: (2025)
by: Kumar, Sonu, et al.
Published: (2025)
When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents
by: Liu, Shi, et al.
Published: (2026)
by: Liu, Shi, et al.
Published: (2026)
Stable Agentic Control: Tool-Mediated LLM Architecture for Autonomous Cyber Defense
by: Prinos, Kerri, et al.
Published: (2026)
by: Prinos, Kerri, et al.
Published: (2026)
MCP Security Bench (MSB): Benchmarking Attacks Against Model Context Protocol in LLM Agents
by: Zhang, Dongsen, et al.
Published: (2025)
by: Zhang, Dongsen, et al.
Published: (2025)
The Granularity Mismatch in Agent Security: Argument-Level Provenance Solves Enforcement and Isolates the LLM Reasoning Bottleneck
by: Fan, Linfeng, et al.
Published: (2026)
by: Fan, Linfeng, et al.
Published: (2026)
Governed MCP: Kernel-Level Tool Governance for AI Agents via Logit-Based Safety Primitives
by: Son, Daeyeon
Published: (2026)
by: Son, Daeyeon
Published: (2026)
I Don't Know You, But I Can Catch You: Real-Time Defense against Diverse Adversarial Patches for Object Detectors
by: Lin, Zijin, et al.
Published: (2024)
by: Lin, Zijin, et al.
Published: (2024)
IPI-proxy: An Intercepting Proxy for Red-Teaming Web-Browsing AI Agents Against Indirect Prompt Injection
by: Chia-Pei, et al.
Published: (2026)
by: Chia-Pei, et al.
Published: (2026)
MCPGuard : Automatically Detecting Vulnerabilities in MCP Servers
by: Wang, Bin, et al.
Published: (2025)
by: Wang, Bin, et al.
Published: (2025)
ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection
by: Zhao, Wei, et al.
Published: (2026)
by: Zhao, Wei, et al.
Published: (2026)
PragLocker: Protecting Agent Intellectual Property in Untrusted Deployments via Non-Portable Prompts
by: Li, Qinfeng, et al.
Published: (2026)
by: Li, Qinfeng, et al.
Published: (2026)
Formalization Driven LLM Prompt Jailbreaking via Reinforcement Learning
by: Wang, Zhaoqi, et al.
Published: (2025)
by: Wang, Zhaoqi, et al.
Published: (2025)
Breaking the Protocol: Security Analysis of the Model Context Protocol Specification and Prompt Injection Vulnerabilities in Tool-Integrated LLM Agents
by: Maloyan, Narek, et al.
Published: (2026)
by: Maloyan, Narek, et al.
Published: (2026)
AdapTools: Adaptive Tool-based Indirect Prompt Injection Attacks on Agentic LLMs
by: Wang, Che, et al.
Published: (2026)
by: Wang, Che, et al.
Published: (2026)
PentestMCP: A Toolkit for Agentic Penetration Testing
by: Ezetta, Zachary, et al.
Published: (2025)
by: Ezetta, Zachary, et al.
Published: (2025)
Simplified and Secure MCP Gateways for Enterprise AI Integration
by: Brett, Ivo
Published: (2025)
by: Brett, Ivo
Published: (2025)
Prompt Inject Detection with Generative Explanation as an Investigative Tool
by: Pan, Jonathan, et al.
Published: (2025)
by: Pan, Jonathan, et al.
Published: (2025)
ToolTweak: An Attack on Tool Selection in LLM-based Agents
by: Sneh, Jonathan, et al.
Published: (2025)
by: Sneh, Jonathan, et al.
Published: (2025)
Cryptographic Runtime Governance for Autonomous AI Systems: The Aegis Architecture for Verifiable Policy Enforcement
by: Mazzocchetti, Adam Massimo
Published: (2026)
by: Mazzocchetti, Adam Massimo
Published: (2026)
RTLMarker: Protecting LLM-Generated RTL Copyright via a Hardware Watermarking Framework
by: Wang, Kun, et al.
Published: (2025)
by: Wang, Kun, et al.
Published: (2025)
Can LLM Prompting Serve as a Proxy for Static Analysis in Vulnerability Detection
by: Ceka, Ira, et al.
Published: (2024)
by: Ceka, Ira, et al.
Published: (2024)
PID: Prompt-Independent Data Protection Against Latent Diffusion Models
by: Li, Ang, et al.
Published: (2024)
by: Li, Ang, et al.
Published: (2024)
Similar Items
-
Don't believe everything you read: Understanding and Measuring MCP Behavior under Misleading Tool Descriptions
by: Li, Zhihao, et al.
Published: (2026) -
MCP Bridge: A Lightweight, LLM-Agnostic RESTful Proxy for Model Context Protocol Servers
by: Ahmadi, Arash, et al.
Published: (2025) -
MCP-ITP: An Automated Framework for Implicit Tool Poisoning in MCP
by: Li, Ruiqi, et al.
Published: (2026) -
Secure Tool Manifest and Digital Signing Solution for Verifiable MCP and LLM Pipelines
by: Jamshidi, Saeid, et al.
Published: (2026) -
CASCADE: A Cascaded Hybrid Defense Architecture for Prompt Injection Detection in MCP-Based Systems
by: Turgut, İpek Abasıkeleş, et al.
Published: (2026)