Trust inversion and its exploitation: A threat model of the Model Context Protocol for agentic AI
The Model Context Protocol (MCP) standardizes connections between large language model applications and external tools and data. Its capability negotiation, dynamic discovery, insertion of tool results into model context, and server-initiated sampling create composition risks when server-originated artefacts influence...