Story · arXiv

Prompts Don't Protect: Architectural Enforcement via MCP Proxy for LLM Tool Access Control (arXiv)

paper · Story page

With unauthorized tools merely visible in context, models invoked them in 48-68% of adversarial scenarios; role-escalation attacks reached 96% on frontier models, and explicit allowlists cut violations to as low as 4% but never zero. An ABAC proxy that filters the MCP registry at discovery time makes unauthorized invocation 0% by design.

In plain words

  • Researchers found that written instructions did not reliably stop artificial intelligence (AI) systems from using forbidden tools they could still see.
  • In hostile tests, these systems chose forbidden tools in 48 to 68 percent of cases despite instructions not to.
  • The proposed software filters the tool list before the AI receives it, removing anything the user cannot access.
  • Organizations can make forbidden tool use impossible by hiding those tools before the AI can choose among them.

Appeared in

Subscribe

Get the brief in your inbox

Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.

  • Weekdays at 8:45am IST, one lead story and 6 to 9 items.
  • Sundays, an argued synthesis rather than a recap.
  • One click to leave, and quiet days say so in the subject line.
How often

Weekdays 8:45am IST + Sundays. Unsubscribe in one click.

You're asking for The Agentic Brief by email at the cadence you picked. You can unsubscribe in one click from any issue, and your address is never sold or shared.