Session

Agents Will Hack Any Approval Surface You Give Them

We built an MCP server with a guard tool pattern — data access requires an unlock token, obtained through human approval on a separate web page. The agent self-approved in under two seconds. We added a password-protected login page. The agent read our source code, found the password, logged in, and approved itself. We moved the approval to a separate port. The agent found it and approved itself there too. This talk presents a series of progressively hardened MCP authorization experiments, each defeated by the agent, leading to the conclusion that approval surfaces must be on architecturally separate origins with authentication the agent cannot obtain. We show the exact attack chains, the code, the logs, and the defense that finally worked: separating the MCP server (agent-accessible) from the registry dashboard (human-authenticated, agent-inaccessible).

Shub Argha

Head of Forward Deployed Engineering @ Arcade.dev

New York City, New York, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top