Prompts Don't Protect: Architectural Enforcement via MCP Proxy for LLM Tool Access Control
This work identifies a critical gap: when unauthorized tools are visible in an agent's context, models select them in 48-68% of adversarial scenarios, even when explicitly instructed not to, and proposes a proxy-enforced attribute-based access control layer for MCP that filters tool registries at discovery time.