MARATTO

article

Addressing Security Gaps in MCP: Design of a Resilient Reference Architecture

Abstract

The Model Context Protocol (MCP) has emerged as a new open standard enabling seamless interaction between Large Language Models (LLMs) and a diverse ecosystem of external tools, services, data sources, and other protocols. The introduction of this new standard has accelerated the development and deployment of AI agents across various domains. However, as a relatively new protocol, its security implications have not been extensively researched. This paper fills this research gap by providing a thorough security analysis of MCP implementations. We identify and document significant security challenges by examining available documentation and open-source projects. Prevalent threats include prompt and SQL injection vulnerabilities, tool poisoning, name squatting, resource exhaustion attacks, and weaknesses in current authentication mechanisms. For each potential vulnerability identified, we propose a specific mitigation strategy. Each identified potential vulnerability is then addressed with a proposed mitigation. Finally, we propose a reference architecture that addresses found security concerns and also assess the performance overhead introduced by each proposed mitigation.

Research topics

  • Scientific Computing and Data Management
  • Web Application Security Vulnerabilities
  • Model-Driven Software Engineering Techniques

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1109/icoa66896.2025.11236877

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.