Skip to content
Search
paperSeptember 2026Unreviewed

ACLE-MCP: Attested Capability Leases for Execution-Time Trust in Remote LLM Tool Use

Zhiyang Ding, Yang Luo, Guangpu Chen, Qingni Shen, Zhonghai Wu

Abstract

Remote Model Context Protocol (MCP) services enable large language model agents to invoke external tools, but OAuth authorization alone does not ensure that a later tool call is executed by the provider-side workload that the relying party intended to trust. An endpoint may remain authorized even after execution shifts to a substituted workload, relies on stale appraisal state, reuses authority transferred from another sender, or traverses an undeclared downstream component. We call this problem

Categories

Framework mappings

OWASP Top 10 for Agentic Applications
  • ASI02Tool Misuse & Exploitation
MITRE ATLAS
  • AML.T0053AI Agent Tool Invocation

Suggested from the entry's categories.

Cite

@misc{ding2026aclemcp,
  title = {{ACLE-MCP: Attested Capability Leases for Execution-Time Trust in Remote LLM Tool Use}},
  author = {Zhiyang Ding and Yang Luo and Guangpu Chen and Qingni Shen and Zhonghai Wu},
  year = {2026},
  month = sep,
  eprint = {2609.02690},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2609.02690}
}