Security of The Model Context Protocol Ecosystem: Emerging Threats, Empirical Attack Evidence, Trust and Authorization Failures, Supply-Chain Risks, And Defensive Strategies
The rapid adoption of agentic artificial intelligence has transformed large language models into agents that can discover tools, access resources, process information, and execute actions in external environments. The Model Context Protocol (MCP) supports this transformation by enabling standardized interaction between AI applications and external services, but it also introduces a security surface in which semantic information, delegated authority, software dependencies, and runtime capabilities intersect. This review provides an evidence-informed assessment of the MCP security ecosystem, drawing on peer-reviewed literature published from 2020 through September 2026, with particular emphasis on empirical evidence from 2025 and 2026. The analysis examines MCP architecture and trust boundaries, tool discovery and selection, authorization and privilege propagation, credential use, cross-tool data exfiltration, malicious servers, supply-chain compromise, implementation vulnerabilities, and the security implications of stateless architectures. Evidence from experimental studies and security benchmarks demonstrates that tool poisoning and metadata manipulation can influence model decisions without malicious prompts, while confused deputy attacks can redirect agents toward adversarial capabilities. Reported experiments show tool selection hijacking rates of up to 90.89% and malicious payload execution rates of up to 86.46%, highlighting the gap between technical authentication and trustworthy authorization. The review further finds that cross-tool workflows can amplify risk even when individual tools appear legitimate, while long-lived credentials, vulnerable dependencies, malicious updates, and weak registry controls can extend attacks across the software supply-chain. Effective protection requires defense in depth rather than reliance on model behavior or server authentication alone. Recommended measures include identity and provenance verification, resource bound and least-privilege authorization, metadata validation, capability restriction, sandboxing, network and egress controls, tool signing and version pinning, software bill of materials and dependency analysis, runtime monitoring, information flow enforcement, and human approval for high-impact actions. The review concludes that MCP security should move from prompt-centric protection toward policy-centric, lifecycle based, and risk-adaptive security, supported by interoperable standards for cryptographic identity, capability attestation, provenance, benchmarking, data-flow enforcement, and security evaluation. This approach is essential for preserving trust, confidentiality, integrity, and autonomy as MCP enabled agents become more widely deployed.
Authors
- David Chinonso Anih
- Khalid D. Muhammed
Institutions
- Federal University of Technology (NG)
Publication Details
- Journal
- Iconic Research and Engineering Journals
- Published
- 2026-09-29
- DOI
- https://doi.org/10.64388/irev10i3-1723420
- Primary Topic
- Scientific Computing and Data Management
- Type
- article
- Field-Weighted Citation Impact
- 0.00