Home / Current Issue / Paper 1723420
Security of The Model Context Protocol Ecosystem: Emerging Threats, Empirical Attack Evidence, Trust and Authorization Failures, Supply-Chain Risks, And Defensive Strategies
Subject area: Science,Engineering and Technology · Area of research: Context Protocol Ecosystem
DOI: 10.64388/IREV10I3-1723420
Abstract
The rapid adoption of agentic artificial intelligence has transformed large language models into agents that can discover tools, access resources, process information, and execute actions in external environments. The Model Context Protocol (MCP) supports this transformation by enabling standardized interaction between AI applications and external services, but it also introduces a security surface in which semantic information, delegated authority, software dependencies, and runtime capabilities intersect. This review provides an evidence-informed assessment of the MCP security ecosystem, drawing on peer-reviewed literature published from 2020 through September 2026, with particular emphasis on empirical evidence from 2025 and 2026. The analysis examines MCP architecture and trust boundaries, tool discovery and selection, authorization and privilege propagation, credential use, cross-tool data exfiltration, malicious servers, supply-chain compromise, implementation vulnerabilities, and the security implications of stateless architectures. Evidence from experimental studies and security benchmarks demonstrates that tool poisoning and metadata manipulation can influence model decisions without malicious prompts, while confused deputy attacks can redirect agents toward adversarial capabilities. Reported experiments show tool selection hijacking rates of up to 90.89% and malicious payload execution rates of up to 86.46%, highlighting the gap between technical authentication and trustworthy authorization. The review further finds that cross-tool workflows can amplify risk even when individual tools appear legitimate, while long-lived credentials, vulnerable dependencies, malicious updates, and weak registry controls can extend attacks across the software supply-chain. Effective protection requires defense in depth rather than reliance on model behavior or server authentication alone. Recommended measures include identity and provenance verification, resource bound and least-privilege authorization, metadata validation, capability restriction, sandboxing, network and egress controls, tool signing and version pinning, software bill of materials and dependency analysis, runtime monitoring, information flow enforcement, and human approval for high-impact actions. The review concludes that MCP security should move from prompt-centric protection toward policy-centric, lifecycle based, and risk-adaptive security, supported by interoperable standards for cryptographic identity, capability attestation, provenance, benchmarking, data-flow enforcement, and security evaluation. This approach is essential for preserving trust, confidentiality, integrity, and autonomy as MCP enabled agents become more widely deployed.
Keywords
Model Context Protocol; agentic artificial intelligence; artificial intelligence security; tool poisoning; confused deputy attacks; authorization and privilege management; supply-chain security; data exfiltration; runtime security
References
[1] M. Abou Ali, F. Dornaika, and J. Charafeddine, “Agentic AI: a comprehensive survey of architectures, applications, and future directions,” Artif Intell Rev., vol. 59, Art. no. 11, 2026. Springer
[2] A. Milani, V. Franzoni, and E. Florindi, “Indirect prompt injection in large language models,” Neural Comput Appl., vol. 38, Art. no. 530, 2026. Springer
[3] B. M. Reichert and R. R. Obelheiro, “Software supply chain security: a systematic literature review,” Int J Comput Appl., vol. 46, no. 10, pp. 853–867, 2024. Taylor & Francis
[4] Y. Xu, Y. Zhuang, X. Liu, T. Zhang, B. Xiao, X. Xu, et al., “LLM agents security duality: a comprehensive survey of self-security and empowered cybersecurity,” Artif Intell Rev., vol. 59, Art. no. 174, 2026. Springer
[5] X. Hou, Y. Zhao, S. Wang, and H. Wang, “Model Context Protocol (MCP): landscape, security threats, and future research directions,” ACM Trans Softw Eng Methodol., 2026. ACM
[6] C. Huang, X. Huang, N. P. Tran, and A. Milani Fard, “Model Context Protocol threat modeling and analysis of vulnerabilities to prompt injection with tool poisoning,” J Cybersecur Priv., vol. 6, no. 3, Art. no. 84, 2026. MDPI
[7] Z. Li, J. Wu, Y. Peng, T. Luo, X. Cui, and X. Ling, “Confused deputy attack against Model Context Protocol,” ACM Trans Softw Eng Methodol., 2026. ACM
[8] Z. Xi, W. Chen, X. Guo, W. He, Y. Ding, B. Hong, et al., “The rise and potential of large language model based agents: a survey,” Sci China Inf Sci., vol. 68, Art. no. 121101, 2025. Springer
[9] B. C. Das, M. H. Amini, and Y. Wu, “Security and privacy challenges of large language models: a survey,” ACM Comput Surv., vol. 57, no. 6, 2025. ACM
[10] M. A. Ferrag, A. Lakas, N. Tihanyi, and M. Debbah, “Securing LLM agents: from prompt sanitization to autonomous red teaming and beyond,” Internet Things Cyber-Phys Syst., vol. 5, pp. 185–209, 2026. ScienceDirect
[11] B. Yan, K. Li, M. Xu, Y. Dong, Y. Zhang, Z. Ren, et al., “On protecting the data privacy of Large Language Models (LLMs) and LLM agents: a literature review,” High-Confidence Comput., vol. 5, no. 2, Art. no. 100300, 2025. ScienceDirect
[12] J. Park, G. Kim, H. Lee, and J. Park, “Beyond tool poisoning: attack surfaces of malicious remote MCP servers across LLM platforms,” Electronics, vol. 15, no. 10, Art. no. 2214, 2026. MDPI
[13] T. Geng, Z. Xu, Y. Qu, and W. E. Wong, “Prompt injection attacks on large language models: a survey of attack methods, root causes, and defense strategies,” Comput Mater Contin., vol. 87, no. 1, Art. no. 4, 2026. Tech Science Press
[14] M. Leo, F. Tan, T. Miao, and G. Anand, “From threat to trust: assessing security risks of agentic AI systems,” Int J Inf Secur., vol. 25, Art. no. 23, 2026. Springer
[15] X. Zhang, C. Zhang, T. Li, Y. Huang, X. Jia, M. Hu, et al., “JailGuard: a universal detection framework for prompt-based attacks on LLM systems,” ACM Trans Softw Eng Methodol., vol. 35, no. 1, pp. 8:1–8:40, 2026. ACM
[16] F. He, T. Zhu, D. Ye, B. Liu, W. Zhou, and P. S. Yu, “The emerged security and privacy of LLM agent: a survey with case studies,” ACM Comput Surv., vol. 58, no. 6, Art. no. 162, 2025. ACM
[17] G. Sato, S. Egami, Y. Tahara, A. Ohsuga, and Y. Sei, “Addressing prompt injection in large language models via in-context learning,” Comput Mater Contin., vol. 87, no. 2, Art. no. 99, 2026. Tech Science Press
[18] Z. Zhang, Q. Li, J. Cao, L. Liu, and J. Ni, “From AI-generated content to agentic action: security and safety threats in generative AI,” J Inf Intell., vol. 4, no. 4, pp. 276–297, 2026. ScienceDirect
[19] S. Du, J. Zhao, J. Shi, Z. Xie, X. Jiang, Y. Bai, et al., “A survey on the optimization of large language model-based agents,” ACM Comput Surv., vol. 58, no. 9, Art. no. 223, 2026. ACM
[20] N. Kshetri, “Transforming cybersecurity with agentic AI to combat emerging cyber threats,” Telecommun Policy, vol. 49, no. 6, Art. no. 102976, 2025. ScienceDirect
[21] I. Adabara, B. O. Sadiq, A. N. Shuaibu, Y. I. Danjuma, and M. Venkateswarlu, “A review of agentic AI in cybersecurity: cognitive autonomy, ethical governance, and quantum-resilient defense,” F1000Res., vol. 14, Art. no. 843, 2025. F1000Research
[22] A. Andreoli, A. Lounis, M. Debbabi, and A. Hanna, “On the prevalence of software supply chain attacks: empirical study and investigative framework,” Forensic Sci Int Digit Investig., vol. 44, Art. no. 301508, 2023. ScienceDirect
[23] B. Hammi and S. Zeadally, “Software supply chain security: issues and countermeasures,” Computer, vol. 56, no. 7, pp. 54–66, 2023. IEEE
[24] Mechri, M. A. Ferrag, and M. Debbah, “SecureQwen: leveraging LLMs for vulnerability detection in Python codebases,” Comput Secur., vol. 148, Art. no. 104151, 2025. ScienceDirect
[25] Edemacu and X. Wu, “Privacy preserving prompt engineering: a survey,” ACM Comput Surv., vol. 57, no. 10, Art. no. 255, 2025. ACM
[26] Z. Deng, Y. Guo, C. Han, W. Ma, J. Xiong, S. Wen, et al., “AI agents under threat: a survey of key security challenges and future pathways,” ACM Comput Surv., vol. 57, no. 7, Art. no. 182, 2025. ACM
[27] Hughes, Y. K. Dwivedi, T. Malik, M. Shawosh, M. A. Albashrawi, I. Jeon, et al., “AI agents and agentic systems: a multi-expert analysis,” J Comput Inf Syst., vol. 65, no. 4, pp. 489–517, 2025.
[28] H. Rebatchi, N. Moha, and T. F. A. Bissyandé, “Dependabot and security pull requests: large empirical study,” Empir Softw Eng., vol. 29, no. 5, 2024. Springer
[29] S. Srinivas, B. Kirk, J. Zendejas, M. Espino, M. Boskovich, A. Bari, et al., “AI-augmented SOC: a survey of LLMs and agents for security automation,” J Cybersecur Priv., vol. 5, no. 4, Art. no. 95, 2025. MDPI
[30] N. Dzhaliuk, D. Sabodashko, V. Khoma, Y. Khoma, V. Kolchenko, and M. Podpora, “Comparative evaluation of machine learning methods for protecting LLMs from prompt injection attacks,” Int J Inf Secur., vol. 25, Art. no. 109, 2026. Springer
[31] H. G. Moia, I. J. Sanz, G. A. F. Rebello, R. D. Meneses, B. Hitaj, and U. Lindqvist, “LLM in the middle: a systematic review of threats and mitigations to real-world LLM-based systems,” Comput Sci Rev., vol. 61, Art. no. 100916, 2026. ScienceDirect
[32] H. Jing, F. Li, Y. Dong, W. Zhou, and R. Liu, “Memory poisoning attacks on retrieval-augmented large language model agents via deceptive semantic reasoning,” Eng Appl Artif Intell., vol. 167, Art. no. 113968, 2026. ScienceDirect
[33] Y. Tang, Y. Liu, J. Lan, Z. Yan, and E. Gelenbe, “Security of LLM-based agents regarding attacks, defenses, and applications: a comprehensive survey,” Inf Fusion, vol. 127, Art. no. 103941, 2026. ScienceDirect
[34] A. Khan, K. AlKhanbashi, and A. Mohamed, “Evaluating indirect prompt injection defenses in tool-using LLM agents: security, utility, and replication,” Computers, vol. 15, no. 9, Art. no. 570, 2026. MDPI
[35] J. Zhang, H. Bu, H. Wen, Y. Liu, H. Fei, R. Xi, et al., “When LLMs meet cybersecurity: a systematic literature review,” Cybersecurity, vol. 8, Art. no. 55, 2025. Springer
[36] E. S. Mathew, “Enhancing security in large language models: a comprehensive review of prompt injection attacks and defenses,” J Artif Intell., vol. 7, no. 1, pp. 347–363, 2025. Tech Science Press
[37] R. B. Hadiprakoso, W. Wilujengning, and A. Amiruddin, “Adaptive multi-layer framework for detecting and mitigating prompt injection attacks in large language models,” J Inf Syst Eng Bus Intell., vol. 11, no. 3, pp. 473–487, 2025. Journal of Information Systems Engineering and Business Intelligence
[38] T. Gokcimen and B. Das, “A novel system for strengthening security in large language models against hallucination and injection attacks with effective strategies,” Alexandria Eng J., vol. 123, pp. 71–90, 2025. ScienceDirect
[39] Böhme, E. Bodden, T. Bultan, C. Cadar, Y. Liu, and G. Scanniello, “Software security analysis in 2030 and beyond: a research roadmap,” ACM Trans Softw Eng Methodol., vol. 34, 2025. ACM
[40] H. Hou, Y. Ma, and J. Miao, “CapAgent: semantic data-flow governance for LLM agents in big-data cognitive computing,” Big Data Cogn Comput., vol. 10, no. 9, Art. no. 293, 2026. MDPI
[41] S. Wang, S. Zhu, and R. Li, “Runtime policy enforcement for MCP-based LLM agents,” Electronics, vol. 15, no. 13, Art. no. 2829, 2026. MDPI
[42] Nageshwaran and S. Ezekiel, “Agentic AI and large language models for autonomous IoT cybersecurity: a systematic survey, taxonomy, and research roadmap,” Electronics, vol. 15, no. 12, Art. no. 2740, 2026. MDPI
[43] Y. Shen, X. Gao, H. Sun, and Y. Guo, “Understanding vulnerabilities in software supply chains,” Empir Softw Eng., vol. 30, Art. no. 20, 2025. Springer
[44] Shu, W. Chen, G. Fan, H. Yu, Z. Huang, and Y. Liang, “Tool or toy: are SCA tools ready for challenging scenarios,” Comput Secur., vol. 158, Art. no. 104624, 2025. ScienceDirect
[45] S. Nocera, S. Romano, M. Di Penta, R. Francese, and G. Scanniello, “On the adoption of software bill of materials in open-source software projects,” J Syst Softw., vol. 230, Art. no. 112540, 2025. ScienceDirect
[46] F. M. Teichmann, “Agentic AI systems as a responsibility-attribution problem in autonomous cyber operations,” Law Innov Technol., 2026. Taylor & Francis
[47] W. B. Mbaka and K. Tuma, “Less is more: usefulness of data flow diagrams and large language models for security threat validation,” Empir Softw Eng., vol. 31, Art. no. 122, 2026. Springer
How to cite this paper
@article{1723420,
author = {Khalid D. Muhammed, David Chinonso Anih},
title = {Security of The Model Context Protocol Ecosystem: Emerging Threats, Empirical Attack Evidence, Trust and Authorization Failures, Supply-Chain Risks, And Defensive Strategies},
journal = {Iconic Research And Engineering Journals},
year = {2026},
volume = {10},
number = {3},
pages = {3266-3314},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1723420.pdf},
abstract = {The rapid adoption of agentic artificial intelligence has transformed large language models into agents that can discover tools, access resources, process information, and execute actions in external environments. The Model Context Protocol (MCP) supports this transformation by enabling standardized interaction between AI applications and external services, but it also introduces a security surface in which semantic information, delegated authority, software dependencies, and runtime capabilities intersect. This review provides an evidence-informed assessment of the MCP security ecosystem, drawing on peer-reviewed literature published from 2020 through September 2026, with particular emphasis on empirical evidence from 2025 and 2026. The analysis examines MCP architecture and trust boundaries, tool discovery and selection, authorization and privilege propagation, credential use, cross-tool data exfiltration, malicious servers, supply-chain compromise, implementation vulnerabilities, and the security implications of stateless architectures. Evidence from experimental studies and security benchmarks demonstrates that tool poisoning and metadata manipulation can influence model decisions without malicious prompts, while confused deputy attacks can redirect agents toward adversarial capabilities. Reported experiments show tool selection hijacking rates of up to 90.89% and malicious payload execution rates of up to 86.46%, highlighting the gap between technical authentication and trustworthy authorization. The review further finds that cross-tool workflows can amplify risk even when individual tools appear legitimate, while long-lived credentials, vulnerable dependencies, malicious updates, and weak registry controls can extend attacks across the software supply-chain. Effective protection requires defense in depth rather than reliance on model behavior or server authentication alone. Recommended measures include identity and provenance verification, resource bound and least-privilege authorization, metadata validation, capability restriction, sandboxing, network and egress controls, tool signing and version pinning, software bill of materials and dependency analysis, runtime monitoring, information flow enforcement, and human approval for high-impact actions. The review concludes that MCP security should move from prompt-centric protection toward policy-centric, lifecycle based, and risk-adaptive security, supported by interoperable standards for cryptographic identity, capability attestation, provenance, benchmarking, data-flow enforcement, and security evaluation. This approach is essential for preserving trust, confidentiality, integrity, and autonomy as MCP enabled agents become more widely deployed.},
keywords = {Model Context Protocol; agentic artificial intelligence; artificial intelligence security; tool poisoning; confused deputy attacks; authorization and privilege management; supply-chain security; data exfiltration; runtime security},
month = {September},
doi = {https://doi.org/10.64388/IREV10I3-1723420}
}