Give Them an Inch and They Will Take a Mile: Understanding and Measuring Caller Identity Confusion in MCP-Based AI Systems
arXiv 2603.07473·high signal
Reveals a fundamental security flaw in Model Context Protocol systems: most MCP servers use persistent authorization states that grant tool access after a single initial auth, making them unable to distinguish different callers invoking the same service. A single authorization decision can inadvertently grant untrusted parties access to sensitive operations. Calls for explicit per-caller authentication and fine-grained per-tool authorization controls.