Skip to content
Search
paperApril 2026Unreviewed

A Formal Security Framework for MCP-Based AI Agents: Threat Taxonomy, Verification Models, and Defense Mechanisms

Nirajan Acharya, Gaurav Kumar Gupta

arXiv.org

Abstract

The Model Context Protocol (MCP), introduced by Anthropic in November 2024 and now governed by the Linux Foundation's Agentic AI Foundation, has rapidly become the de facto standard for connecting large language model (LLM)-based agents to external tools and data sources, with over 97 million monthly SDK downloads and more than 177000 registered tools. However, this explosive adoption has exposed a critical gap: the absence of a unified, formal security framework capable of systematically charac

Categories

Cite

@misc{acharya2026formal,
  title = {{A Formal Security Framework for MCP-Based AI Agents: Threat Taxonomy, Verification Models, and Defense Mechanisms}},
  author = {Nirajan Acharya and Gaurav Kumar Gupta},
  year = {2026},
  month = apr,
  eprint = {2604.05969},
  archivePrefix = {arXiv},
  doi = {10.48550/arXiv.2604.05969},
  url = {https://www.semanticscholar.org/paper/f28a78235a0ec6bc74135a46688a5008a38044d9}
}