← Highlights

TalkSpeaker

Speaking at CloudX

By Sachin Gupta
Portrait of Sachin Gupta rendered in binary

Talk and demo at CloudX 2026 on defending Model Context Protocol agents against attacks that arrive through the tools they already trust, built on ShieldMCP and the SAFE-MCP technique catalogue.

Spoke on the CloudX Expo Innovation Stage on 3 September, in a 25 minute best practices session, on defending agents that speak the Model Context Protocol (MCP).

Most work on language-model safety guards the user prompt. MCP agents face a different problem: the attack arrives through the tools the agent already trusts. A poisoned tool description, a hidden instruction inside a tool response, or a malicious server pulled from a public registry can redirect an agent without ever touching what the user typed.

The session works from the threat taxonomy in SAFE-MCP, the Linux Foundation and OpenSSF security project I contribute to, which catalogues more than 80 attack techniques against the protocol. It covers tool poisoning and indirect injection among them, then demonstrates ShieldMCP, an open-source runtime defence proxy for MCP. The ShieldMCP research was accepted and published at the ACL 2026 Industry Track and accepted to the EMNLP 2026 System Demonstrations Track.

Related

Tagged