Trust inversion and its exploitation: A threat model of the Model Context Protocol for agentic AI
Résumé
The Model Context Protocol (MCP) standardizes connections between large language model applications and external tools and data. Its capability negotiation, dynamic discovery, insertion of tool results into model context, and server-initiated sampling create composition risks when server-originated artefacts influence actions executed under client authority. We define trust inversion as a condition in which an artefact crossing from a less-trusted MCP component into the client decision context is interpreted as operational authority without provenance-bound policy re-evaluation. The term is used as an MCP-specific analytical lens, not as a replacement for confused-deputy, indirect prompt-injection, control/data-plane-confusion, or transitive-authorization concepts. We construct an architecture-level threat model using three deployment profiles---local stdio, remote Streamable HTTP, and multi-server---together with STRIDE classification, explicit assets and security objectives, and a five-by-five likelihood--impact matrix. Publicly documented demonstrations, guidance-based attack classes, and an implementation CVE are coded by actor, preconditions, attack path, affected layer, violated property, and candidate controls. The analysis groups risks into descriptor and capability drift, cross-tool trust propagation, and sampling-mediated server influence, while separating protocol, ecosystem, implementation, and deployment weaknesses. We propose immediately deployable controls, including transport authentication, least privilege, trust-zone separation, schema validation, sandboxing, and audit logging, and distinguish them from extensions requiring standardization, including signed capability manifests and re-attestation. The resulting checklist is a threat-modelling aid; its mitigation effectiveness remains to be established through prototype implementation, red-team testing, and deployment-specific evaluation.
Citer ce document
Accès au document
Texte intégral en lecture en ligne, réservé aux abonnés SPHAERO et aux membres de l'institution. Se connecter
Voir l'article sur le site de la revueAuteur(s)
Statistiques
Consultations : 1
Téléchargements : 0