about
Systemization of Knowledge: Security and Safety Challenges in MCP (arxiv.org)
3 points by sambhu 298 days ago | hide | past | pdf | discuss on HN

In plain words: A review of the Model Context Protocol, the plug-in standard that lets AI assistants use data and tools, separating attacks from honest mistakes. It shows how context can be rigged to make agents act without permission, and surveys fixes like signed tool records.

Abstract · Systematization of Knowledge: Security and Safety in the Model Context Protocol Ecosystem

The Model Context Protocol (MCP) has emerged as the de facto standard for connecting Large Language Models (LLMs) to external data and tools, effectively functioning as the "USB-C for Agentic AI." While this decoupling of context and execution solves critical interoperability challenges, it introduces a profound new threat landscape where the boundary between epistemic errors (hallucinations) and security breaches (unauthorized actions) dissolves. This Systematization of Knowledge (SoK) aims to provide a comprehensive taxonomy of risks in the MCP ecosystem, distinguishing between adversarial security threats (e.g., indirect prompt injection, tool poisoning) and epistemic safety hazards (e.g., alignment failures in distributed tool delegation). We analyze the structural vulnerabilities of MCP primitives, specifically Resources, Prompts, and Tools, and demonstrate how "context" can be weaponized to trigger unauthorized operations in multi-agent environments. Furthermore, we survey state-of-the-art defenses, ranging from cryptographic provenance (ETDI) to runtime intent verification, and conclude with a roadmap for securing the transition from conversational chatbots to autonomous agentic operating systems.

Shiva Gaire, Srijan Gyawali, Saroj Mishra, Suman Niroula, Dilip Thakur, Umesh Yadav
arXiv:2512.08290 · cs.CR, cs.AI · submitted Dec 9, 2025 · updated Dec 13, 2025
abstract · pdf · html · All authors contributed equally to this work

add comment on HN