Research
Prompts Don't Protect: Architectural MCP Proxy Enforcement Needed for LLM Tool Access Control
When unauthorized tools are visible in an agent's context, LLMs select them in adversarial scenarios regardless of prompt-based restrictions. This paper demonstrates that prompt-level access control is fundamentally insufficient and proposes an architectural enforcement layer via an MCP proxy that filters tool visibility before the model sees it. The approach eliminates unauthorized tool selection without degrading task performance on authorized tools.
Source
↳ Follow the thread