Skip to content
Review Open access

Artificial Intelligence - Model Context Protocol - Review of Real-World Security Threats

Sep 2026 · The Pinnacle: A Journal by Scholar-Practitioners · 0 citations · 2 references

TL;DR

The findings demonstrate that safeguarding agentic AI frameworks require multi-layered technical controls, zero-trust architecture, automated schema validation, and strict identity governance, rather than reliance on static boundary controls.

Abstract

Modern Artificial Intelligence (AI) infrastructures and Model Context Protocol (MCP) deployments face systemic security exposures as a result of autonomous agents interacting directly with external databases and tools. Protocol-level weaknesses, permissive access rights, and unverified third-party repositories allow attackers to execute prompt injection attacks, exfiltrate credentials, and manipulate tool metadata schemas. This paper examines security incidents across five primary domains: tool and server security, prompt and context security, data security and privacy, system and operational security, and authentication and identity security. Underlying root causes and effective mitigation strategies are explored through real-world case studies, including supply chain compromises, cross-repository data leaks, path traversal flaws, and authentication failures. The findings demonstrate that safeguarding agentic AI frameworks require multi-layered technical controls, zero-trust architecture, automated schema validation, and strict identity governance, rather than reliance on static boundary controls.

Read PDF

Similar papers

Review Open access Sep 2026

Security of The Model Context Protocol Ecosystem: Emerging Threats, Empirical Attack Evidence, Trust and Authorization Failures, Supply-Chain Risks, And Defensive Strategies

- The rapid adoption of agentic artificial intelligence has transformed large language models into agents that can discover tools, access resources, process information, and execute actions in external environments. The Model Context Protocol (MCP) supports this transformation by enabling standardized interaction betwe...

Khalid D. Muhammed, David Chinonso Anih · 0 citations
Open access Sep 2026

Security Architecture for Agentic AI in Enterprise Cloud Environments: A Zero-Trust Framework for Secure Autonomous Systems

Agentic artificial intelligence expands the enterprise security boundary because autonomous agents can plan tasks, retain memory, invoke tools, call APIs, and initiate business actions. Authentication at session start is therefore insufficient when later actions may be influenced by untrusted content, poisoned memory,...

S. Suryawanshi · 0 citations
Review Open access Sep 2026

The Security Duality of Large Language Model Agents: A Systematic Review of Self-Security Protection and Cybersecurity Empowerment

Large Language Model (LLM) agents integrate memory, tool invocation, environment interaction, and multi-agent collaboration, evolving from passive text-generation tools into autonomous systems that execute complex tasks. This capability leap creates a pronounced security duality. On the one hand, LLM agents face emergi...

Da Fu, Da-Lin Xiang · 0 citations
#artificial intelligence Review Sep 2026

Trustworthy Agentic AI: Failure Modes, Mitigation Strategies, and a Lifecycle Framework for Autonomous LLM Systems

Agentic AI systems built on large language models can plan over multiple steps, use external tools, retain information in memory, and coordinate with other agents. These capabilities make them more useful than static language models, but they also introduce new security and operational risks. Untrusted content from web...

Fayeq Jeelani Syed, Rehan Ahmad, Ali Al Bataineh et al. · 0 citations
Preprint Aug 2026

Beyond the Mandate: A Systematic Security Analysis of the Agent Payments Protocol (AP2)

A systematic security analysis of AP2 v0.2 based on its roles, transaction lifecycle, deployment architectures, and trust boundaries shows that valid mandate signatures alone do not ensure that an agent-mediated transaction reflects the user's intent when its pre-authorization context is manipulated.

A. Aviv, Parth A. Gandh, Ron Bitton et al. · 0 citations
Open access Sep 2026

Runtime Policy Firewall: A Zero-Trust Governance Layer for Enterprise Agentic AI

Enterprise adoption of generative AI is shifting from passive question answering to autonomous agentic execution. Modern agents can decompose goals, retrieve business context, call tools, update records, send messages, initiate transactions, and coordinate workflows across multiple systems. This creates productivity op...

Swapneswar Ray · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.