Loading…
Thursday August 13, 2026 10:55 - 11:20 KST
Most MCP deployments implicitly trust the LLM. If the model says call this tool with these parameters, the server calls it. That trust model is wrong — and at enterprise scale, it is catastrophic. This talk reframes MCP server design through a zero-trust lens: every tool invocation is treated as an untrusted external request that must be authenticated, authorized, validated, rate-limited, and audited independently of who initiated it. I'll demonstrate a zero-trust MCP middleware layer that enforces four controls: (1) per-call JWT audience binding so a tool call valid in one agent context is rejected in another, (2) schema-level input validation with content-addressable allow-lists to prevent prompt injection via tool parameters, (3) capability scoping — tools declare what filesystem paths, network ranges, and data stores they may access, enforced by a policy engine at runtime, and (4) immutable audit logs using append-only signed ledger entries. Live demos include intercepting and blocking a prompt injection attack mid-flight. Code ships as open-source middleware compatible with any MCP SDK.
Speakers
avatar for Unnati Mishra

Unnati Mishra

Software Engineer 2, Independent
Unnati is working as a R&D Engineer Software 2 at VMware by Broadcom, India. Currently working with the Release Engg team of the Tanzu Kubernetes Grid. She has been active in Open Source community since 2019 and has also participated in many Hackathons, bagging prizes in few of them... Read More →
avatar for Akshat Khanna

Akshat Khanna

Machine Learning Engineer II, Independent
Akshat Khanna is a Machine Learning Engineer II at Angel One, where he builds GenAI-powered bots and leverages agentic AI for high-performance trading platforms. Previously, he worked as MTS II at VMware Tanzu, focusing on Kubernetes solutions for the edge. He is an active open-source... Read More →
Thursday August 13, 2026 10:55 - 11:20 KST
Grand Ballroom 1 + 2

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link