Tool-enabled language-model agents introduce new security risks because their behavior evolves over multi-step workflows, yet existing defenses primarily rely on static allowlists or infrastructure isolation. This article presents MCP-Secure, a lightweight, host-side enforcement layer for the Model Context Protocol (MCP) that applies scoped access, read-only defaults, and approval-gated privilege elevation at runtime. MCP-Secure tracks permissions through a session-level state machine and mediates every tool invocation without modifying agents or MCP servers. We evaluate the framework across 1,080 executions spanning multiple models, tasks, and adversarial simulations. Results show that scoped access alone blocks most unsafe behaviors, read-only enforcement reliably neutralizes all mutating attack vectors, and approval-gated elevation maintains strong safety while enabling controlled write operations. Across configurations, the wrapper also shapes agent planning, reducing unsafe attempts as policies tighten. These findings demonstrate that MCP-Secure provides a practical, reproducible mechanism for enforcing least-privilege constraints in tool-enabled LLM systems, offering strong adversarial resistance with interpretable safety– utility trade-offs.
Paper
Full text
MCP-Secure: A Runtime Access Control Layer for Privilege-Aware LLM Agent Tooling
Semantic Scholar · Computer Science · 2026
Abstract
Tool-enabled language-model agents introduce new security risks because their behavior evolves over multi-step workflows, yet existing defenses primarily rely on static allowlists or infrastructure isolation. This article presents MCP-Secure, a lightweight, host-side enforcement layer for the Model Context Protocol (MCP) that applies scoped access, read-only defaults, and approval-gated privilege elevation at runtime. MCP-Secure tracks permissions through a session-level state machine and mediates every tool invocation without modifying agents or MCP servers. We evaluate the framework across 1,080 executions spanning multiple models, tasks, and adversarial simulations. Results show that scoped access alone blocks most unsafe behaviors, read-only enforcement reliably neutralizes all mutating attack vectors, and approval-gated elevation maintains strong safety while enabling controlled write operations. Across configurations, the wrapper also shapes agent planning, reducing unsafe attempts as policies tighten. These findings demonstrate that MCP-Secure provides a practical, reproducible mechanism for enforcing least-privilege constraints in tool-enabled LLM systems, offering strong adversarial resistance with interpretable safety– utility trade-offs.
References (19)
Scroll for more · 7 remaining