{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,18]],"date-time":"2026-08-18T01:47:56Z","timestamp":1787017676480,"version":"build-2736575974"},"reference-count":64,"publisher":"Association for Computing Machinery (ACM)","issue":"FSE","license":[{"start":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T00:00:00Z","timestamp":1782777600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/501100001711","name":"Swiss National Science Foundation","doi-asserted-by":"crossref","award":["10001777"],"award-info":[{"award-number":["10001777"]}],"id":[{"id":"10.13039\/501100001711","id-type":"DOI","asserted-by":"crossref"}]},{"name":"European Union\u2019s Horizon research and innovation programme","award":["101189899"],"award-info":[{"award-number":["101189899"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Proc. ACM Softw. Eng."],"published-print":{"date-parts":[[2026,6,30]]},"abstract":"<jats:p>Large Language Models (LLMs) have evolved into AI agents that interact with external tools and environments to perform complex tasks. The Model Context Protocol (MCP) has become the de facto standard for connecting agents with such resources, but security has lagged behind: thousands of MCP servers execute with unrestricted access to host systems, creating a broad attack surface. In this paper, we introduce AgentBound, the first access control framework for MCP servers. AgentBound combines a declarative policy mechanism, inspired by the Android permission model, with a policy enforcement engine that contains malicious behavior without requiring MCP server modifications. We build a dataset containing the 296 most popular MCP servers, and show that access control policies can be generated automatically from source code with 80.9% accuracy. We also show that AgentBound blocks the majority of security threats in several malicious MCP servers, and that the policy enforcement engine introduces negligible overhead. Our contributions provide developers and project managers with a foundation for securing MCP servers while maintaining productivity, enabling researchers and tool builders to explore new directions for declarative access control and MCP security.<\/jats:p>","DOI":"10.1145\/3808103","type":"journal-article","created":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T17:06:14Z","timestamp":1782839174000},"page":"2141-2164","source":"Crossref","is-referenced-by-count":1,"title":["AgentBound: Securing Execution Boundaries of AI Agents"],"prefix":"10.1145","volume":"3","author":[{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0002-2224-1687","authenticated-orcid":false,"given":"Christoph","family":"B\u00fchler","sequence":"first","affiliation":[{"name":"University of St. Gallen, St. Gallen, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0002-7825-3409","authenticated-orcid":false,"given":"Matteo","family":"Biagiola","sequence":"additional","affiliation":[{"name":"University of St. Gallen, St. Gallen, Switzerland"},{"name":"USI Lugano, Lugano, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0002-5306-8645","authenticated-orcid":false,"given":"Luca","family":"Di Grazia","sequence":"additional","affiliation":[{"name":"University of St. Gallen, St. Gallen, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0002-9324-8894","authenticated-orcid":false,"given":"Guido","family":"Salvaneschi","sequence":"additional","affiliation":[{"name":"University of St. Gallen, St. Gallen, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,30]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/3605764.3623985"},{"key":"e_1_2_1_2_1","unstructured":"Ofir Abu. When Public Prompts Turn Into Local Shells: 'CurXecute' -RCE in Cursor via MCP Auto-Start | AIM. url: https:\/\/2.zoppoz.workers.dev:443\/https\/www.aim.security\/post\/when-public-prompts-turn-into-localshells-rce-in-cursor-via-mcp-auto-start (visited on 09\/11\/2025)."},{"key":"e_1_2_1_3_1","volume-title":"LLM-agnostic Restful Proxy for Model Context Protocol Servers.","author":"Ahmadi Arash","year":"2026","unstructured":"Arash Ahmadi, Sarah Sharif, and Yaser M. Banad. MCP Bridge: A Lightweight, LLM-agnostic Restful Proxy for Model Context Protocol Servers. 2026. arXiv: 2504 . 08999 [cs.CR]. url: https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/2504.08999 (visited on 02\/24\/2026). Pre-published."},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-025-11458-6"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1002\/9781119644682"},{"key":"e_1_2_1_6_1","volume-title":"Anthropic.","year":"2024","unstructured":"Anthropic. Introducing the Model Context Protocol. Anthropic. Nov. 25, 2024. url: https : \/\/www.anthropic.com\/news\/model-context-protocol (visited on 07\/29\/2025)."},{"key":"e_1_2_1_7_1","first-page":"217","volume-title":"Proceedings of the 2012 ACM conference on Computer and communications security.","author":"Yee Kathy Wain","year":"2012","unstructured":"Kathy Wain Yee Au et al. \"Pscout: analyzing the android permission specification\". In: Proceedings of the 2012 ACM conference on Computer and communications security. 2012, pp. 217-228."},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.3390\/fi17090404"},{"key":"e_1_2_1_9_1","volume-title":"Introducing MCP-Scan: Protecting MCP with Invariant. Accessed 2025-07-25","author":"Beurer-Kellner Luca","year":"2025","unstructured":"Luca Beurer-Kellner and Marc Fischer. Introducing MCP-Scan: Protecting MCP with Invariant. Accessed 2025-07-25. Apr. 2025. url: https:\/\/2.zoppoz.workers.dev:443\/https\/invariantlabs.ai\/blog\/introducing-mcp-scan (visited on 07\/24\/2025)."},{"issue":"1","key":"e_1_2_1_10_1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3301285","article-title":"A survey on various threats and current state of security in android platform","volume":"52","author":"Bhat Parnika","year":"2019","unstructured":"Parnika Bhat and Kamlesh Dutta. \"A survey on various threats and current state of security in android platform\". In: ACM Computing Surveys (CSUR) 52.1 (2019), pp. 1-35.","journal-title":"ACM Computing Surveys (CSUR)"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3338498.3358654"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.3390\/a18080499"},{"key":"e_1_2_1_13_1","first-page":"1877","volume-title":"Advances in neural information processing systems 33","author":"Tom Brown","year":"2020","unstructured":"Tom Brown et al. \"Language models are few-shot learners\". In: Advances in neural information processing systems 33 (2020), pp. 1877-1901."},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.5281\/zenodo.19571298"},{"key":"e_1_2_1_15_1","first-page":"03374","article-title":"Evaluating Large Language Models Trained on Code","author":"Mark Chen","year":"2021","unstructured":"Mark Chen et al. \"Evaluating Large Language Models Trained on Code\". In: CoRR abs\/2107. 03374 (2021). arXiv: 2107.03374. url: https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/2107.03374.","journal-title":"CoRR abs\/2107."},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2401.03428"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.2601.08012"},{"key":"e_1_2_1_18_1","volume-title":"mcp-watch: A comprehensive security scanner for Model Context Protocol (MCP) servers. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/kapilduraphe\/mcp-watch. Accessed 2025-09-02","author":"Duraphe Kapil","year":"2025","unstructured":"Kapil Duraphe. mcp-watch: A comprehensive security scanner for Model Context Protocol (MCP) servers. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/kapilduraphe\/mcp-watch. Accessed 2025-09-02. 2025."},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.2506.13666"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISPASS.2015.7095802"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.2411.04468"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.2410.14923"},{"key":"e_1_2_1_23_1","unstructured":"GitHub -harishsg993010\/damn-vulnerable-MCP-server: Damn Vulnerable MCP Server. https: \/\/github.com\/harishsg993010\/damn-vulnerable-MCP-server. [Accessed 10-09-2025]."},{"key":"e_1_2_1_24_1","unstructured":"Google. Manifest.Permission | API Reference. Android Developers. url: https:\/\/2.zoppoz.workers.dev:443\/https\/developer. android.com\/reference\/android\/Manifest.permission (visited on 08\/19\/2025)."},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2509.25292"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2402.01680"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.2506.13538"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","unstructured":"\/ARXIV.2506.13538. arXiv: 2506.13538. url: https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.48550\/arXiv.2506.13538. 10.48550\/arXiv.2506.13538","DOI":"10.48550\/arXiv.2506.13538"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.2505.24201"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1016\/j"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.2503.23278"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.2505.14590"},{"key":"e_1_2_1_33_1","unstructured":"JSON-PRC Working Group. JSON-RPC 2.0 Specification. Mar. 26 2010. url: https:\/\/2.zoppoz.workers.dev:443\/https\/www. jsonrpc.org\/specification (visited on 07\/29\/2025)."},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2506.19676"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.2504.12757"},{"key":"e_1_2_1_36_1","volume-title":"MCP-Gateway: A plugin-based security gateway for Model Context Protocol (MCP) servers. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/lasso-security\/mcp-gateway. Accessed 2025-09-02","year":"2025","unstructured":"Lasso-Security. MCP-Gateway: A plugin-based security gateway for Model Context Protocol (MCP) servers. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/lasso-security\/mcp-gateway. Accessed 2025-09-02. 2025."},{"key":"e_1_2_1_37_1","volume-title":"We Urgently Need Privilege Management in MCP: A Measurement of API Usage in MCP Ecosystems","author":"Zhihao Li","year":"2025","unstructured":"Zhihao Li et al. We Urgently Need Privilege Management in MCP: A Measurement of API Usage in MCP Ecosystems. 2025. arXiv: 2507.06250 [cs.CR]. url: https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/2507.06250."},{"key":"e_1_2_1_38_1","volume-title":"Engineering AI Judge Systems\". In: arXiv preprint arXiv:2411.17793","author":"Jiahuei Lin","year":"2024","unstructured":"Jiahuei Lin et al. \"Engineering AI Judge Systems\". In: arXiv preprint arXiv:2411.17793 (2024)."},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.2305.13860"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2503.21460"},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.4230\/LIPIcs.ECOOP.2024.27"},{"key":"e_1_2_1_42_1","unstructured":"MCP Server Directory: 6010+ updated daily | PulseMCP -pulsemcp.com. https:\/\/2.zoppoz.workers.dev:443\/https\/www.pulsemcp. com\/servers. [Accessed 10-09-2025]."},{"key":"e_1_2_1_43_1","volume-title":"Claude, VS Code and Windsurf. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/MCP- Defender\/MCP-Defender. Accessed 2025-09-02.","year":"2025","unstructured":"MCP-Defender. MCP-Defender: Desktop app that automatically scans and blocks malicious MCP traffic in AI apps like Cursor, Claude, VS Code and Windsurf. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/MCP- Defender\/MCP-Defender. Accessed 2025-09-02. 2025."},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.2503.04479"},{"key":"e_1_2_1_45_1","volume-title":"Specification. Model Context Protocol.","year":"2025","unstructured":"modelcontextprotocol.io contributors. Specification. Model Context Protocol. June 18, 2025. url: https:\/\/2.zoppoz.workers.dev:443\/https\/modelcontextprotocol.io\/specification\/2025-06-18 (visited on 07\/29\/2025)."},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/IC2E.2015.74"},{"key":"e_1_2_1_47_1","unstructured":"NachoBecerra. Severe Data Loss Caused by GitHub Copilot -Request for Acknowledgment and Compensation \u2022 Community \u2022 Discussion #166370. GitHub. url: https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/orgs\/ community\/discussions\/166370 (visited on 09\/11\/2025)."},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.2504.08623"},{"key":"e_1_2_1_49_1","volume-title":"Function Calling and Other API Updates","author":"AI.","year":"2024","unstructured":"OpenAI. Function Calling and Other API Updates. Mar. 13, 2024. url: https:\/\/2.zoppoz.workers.dev:443\/https\/openai.com\/ index\/function-calling-and-other-api-updates\/ (visited on 08\/21\/2025)."},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/3697010"},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2025.3585609"},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2504.03767"},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-11599-3_5"},{"key":"e_1_2_1_54_1","volume-title":"MCP-Shield: Security scanner for MCP (Model Context Protocol) servers. https: \/\/github.com\/riseandignite\/mcp-shield. Accessed 2025-09-02","year":"2025","unstructured":"riseandignite. MCP-Shield: Security scanner for MCP (Model Context Protocol) servers. https: \/\/github.com\/riseandignite\/mcp-shield. Accessed 2025-09-02. 2025."},{"key":"e_1_2_1_55_1","first-page":"2421","volume-title":"34th USENIX Security Symposium (USENIX Security 25). 2025","author":"Russinovich Mark","year":"2025","unstructured":"Mark Russinovich, Ahmed Salem, and Ronen Eldan. \"Great, Now Write an Article About That: The Crescendo Multi-Turn LLM Jailbreak Attack\". In: 34th USENIX Security Symposium (USENIX Security 25). 2025, pp. 2421-2440. isbn: 978-1-939133-52-6. url: https:\/\/2.zoppoz.workers.dev:443\/https\/www. usenix.org\/conference\/usenixsecurity25\/presentation\/russinovich (visited on 09\/09\/2025)."},{"key":"e_1_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.inffus.2025.103599"},{"key":"e_1_2_1_57_1","volume-title":"Beyond the Protocol: Unveiling Attack Vectors in the Model Context Protocol (MCP) Ecosystem","author":"Hao Song","year":"2025","unstructured":"Hao Song et al. Beyond the Protocol: Unveiling Attack Vectors in the Model Context Protocol (MCP) Ecosystem. 2025. arXiv: 2506.02040 [cs.CR]. url: https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/2506.02040."},{"key":"e_1_2_1_58_1","unstructured":"Unosecur. AI Agent Wiped Live DB: 4-Step Identity-First Security Plan. url: https:\/\/2.zoppoz.workers.dev:443\/https\/www. unosecur.com\/blog\/when-an-ai-agent-wipes-a-live-database-identity-first-controls-tostop-agentic-ai-disasters (visited on 08\/21\/2025)."},{"key":"e_1_2_1_59_1","volume-title":"Jack Vanlightly.","author":"Vanlightly Jack","year":"2025","unstructured":"Jack Vanlightly. Remediation: What Happens after AI Goes Wrong? Jack Vanlightly. July 28, 2025. url: https:\/\/2.zoppoz.workers.dev:443\/https\/jack-vanlightly.com\/blog\/2025\/7\/28\/remediation-what-happens-after-aigoes-wrong (visited on 09\/11\/2025)."},{"key":"e_1_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/OJCS.2025.3589638"},{"key":"e_1_2_1_61_1","volume-title":"A new era in llm security: Exploring security concerns in real-world llm-based systems\". In: arXiv preprint arXiv:2402.18649","author":"Fangzhou Wu","year":"2024","unstructured":"Fangzhou Wu et al. \"A new era in llm security: Exploring security concerns in real-world llm-based systems\". In: arXiv preprint arXiv:2402.18649 (2024)."},{"key":"e_1_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2310.10634"},{"key":"e_1_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.2306.02224"},{"key":"e_1_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1145\/3650212.3680384"}],"container-title":["Proceedings of the ACM on Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/pdf\/10.1145\/3808103","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T18:35:01Z","timestamp":1782844501000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/10.1145\/3808103"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,30]]},"references-count":64,"journal-issue":{"issue":"FSE","published-print":{"date-parts":[[2026,6,30]]}},"alternative-id":["10.1145\/3808103"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/3808103","relation":{},"ISSN":["2994-970X"],"issn-type":[{"value":"2994-970X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,30]]}}}