Session
Securing the Agentic Tool Layer: A Runtime Defense Framework for MCP Agent Deployments
Most LLM safety work guards the user prompt. MCP agents face a different problem: the attack arrives through the tools the agent already trusts. A poisoned tool description, a hidden instruction in a tool response, or a malicious server pulled from a public registry can hijack an agent without ever touching the user.
This demo and presentation is built on ShieldMCP, an open-source runtime defense proxy for MCP whose research was accepted and published at the ACL 2026 Industry Track (A* venue) and accepted to the EMNLP 2026 System Demonstrations Track (A* venue), and on SAFE-MCP, the Linux Foundation / OpenSSF security project I contribute to that catalogues 80+ attack techniques against the Model Context Protocol.
We start with the threat taxonomy from SAFE-MCP: tool poisoning, indirect prompt injection via tool responses, rug-pull servers that change behavior after approval, cross-server shadowing, and exfiltration through legitimate-looking tool arguments.
Then we go inside ShieldMCP's architecture: a transparent proxy that sits between any MCP client and server, inspects tool descriptions at discovery time, validates every tool call and response inline, enforces per-tool policies, and blocks or quarantines suspicious traffic, all with zero changes to the agent, the model, or the server.
Attendees leave with a concrete, deployable defense architecture, the false-positive and latency trade-offs that actually matter in production, a checklist for vetting an MCP server before approving it for their stack, and a link to the open-source code to try it themselves.
Sachin Gupta
Technical Leader at eBay
San Jose, California, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top