article
The Model Context Protocol (MCP) has emerged as a new open standard enabling seamless interaction between Large Language Models (LLMs) and a diverse ecosystem of external tools, services, data sources, and other protocols. The introduction of this new standard has accelerated the development and deployment of AI agents across various domains. However, as a relatively new protocol, its security implications have not been extensively researched. This paper fills this research gap by providing a thorough security analysis of MCP implementations. We identify and document significant security challenges by examining available documentation and open-source projects. Prevalent threats include prompt and SQL injection vulnerabilities, tool poisoning, name squatting, resource exhaustion attacks, and weaknesses in current authentication mechanisms. For each potential vulnerability identified, we propose a specific mitigation strategy. Each identified potential vulnerability is then addressed with a proposed mitigation. Finally, we propose a reference architecture that addresses found security concerns and also assess the performance overhead introduced by each proposed mitigation.
This page summarises published work. The authoritative version sits with the publisher.
DOI: 10.1109/icoa66896.2025.11236877
Is something wrong with this record? Report it or request removal.
Discussion
Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.
No discussion yet. Open the first thread.
New to MARATTO™? Create a free account.