September 2026Unreviewed
ACLE-MCP: Attested Capability Leases for Execution-Time Trust in Remote LLM Tool Use
Zhiyang Ding, Yang Luo, Guangpu Chen, Qingni Shen, Zhonghai Wu
Abstract
Remote Model Context Protocol (MCP) services enable large language model agents to invoke external tools, but OAuth authorization alone does not ensure that a later tool call is executed by the provider-side workload that the relying party intended to trust. An endpoint may remain authorized even after execution shifts to a substituted workload, relies on stale appraisal state, reuses authority transferred from another sender, or traverses an undeclared downstream component. We call this problem
Categories
Framework mappings
OWASP Top 10 for Agentic Applications
- ASI02Tool Misuse & Exploitation
MITRE ATLAS
- AML.T0053AI Agent Tool Invocation
Suggested from the entry's categories.
Cite
@misc{ding2026aclemcp,
title = {{ACLE-MCP: Attested Capability Leases for Execution-Time Trust in Remote LLM Tool Use}},
author = {Zhiyang Ding and Yang Luo and Guangpu Chen and Qingni Shen and Zhonghai Wu},
year = {2026},
month = sep,
eprint = {2609.02690},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2609.02690}
}