Removing the Tenant ID From an MCP Tool Schema Blocks Cross-Tenant Reads That a Validated Parameter Let Through 26 Times Out of 26
Multi-tenant tools that accept a tenant identifier and validate it against the caller's entitlement delegate resource selection to a process whose context may contain attacker-controlled instructions. In a 373-trial ablation across eight model configurations and two transports, the correctly validated tenant parameter served every out-of-scope attempt, 26 of 26. With the parameter removed from the MCP schema and scope bound to a verified credential below the agent, no tool signature could express the read, though 12 of 56 trials escaped by forging writable scope, showing interface invariance needs cryptographically protected context. On production data, set-valued scope caused a measured 57x latency ratio under function-wrapped membership predicates until a JSON_TABLE lateral join recovered index access.
↳ Follow the thread