Story · arXiv
Prompts Don't Protect: Architectural Enforcement via MCP Proxy for LLM Tool Access Control (arXiv)
paper · Story page
With unauthorized tools merely visible in context, models invoked them in 48-68% of adversarial scenarios; role-escalation attacks reached 96% on frontier models, and explicit allowlists cut violations to as low as 4% but never zero. An ABAC proxy that filters the MCP registry at discovery time makes unauthorized invocation 0% by design.
In plain words
- Researchers found that written instructions did not reliably stop artificial intelligence (AI) systems from using forbidden tools they could still see.
- In hostile tests, these systems chose forbidden tools in 48 to 68 percent of cases despite instructions not to.
- The proposed software filters the tool list before the AI receives it, removing anything the user cannot access.
- Organizations can make forbidden tool use impossible by hiding those tools before the AI can choose among them.
Appeared in
- Realistic prompts drop coding-agent scores, and tool filtering beats prompt rules
Sep 01, 2026 · in the sections
Subscribe
Get the brief in your inbox
Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.
- Weekdays at 8:45am IST, one lead story and 6 to 9 items.
- Sundays, an argued synthesis rather than a recap.
- One click to leave, and quiet days say so in the subject line.