Loading…
Friday August 14, 2026 11:30 - 11:55 KST
As MCP systems move from single tool use to multi server and multi agent workflows, a key security question appears: when one server calls another on behalf of a user, whose authority is actually used. In this talk I show how chained MCP calls can create a confused deputy scenario where a server unintentionally uses its own higher privileges instead of the user’s limited permissions, leading to privilege escalation and capability leakage. I demonstrate this with a working multi server setup that exposes three concrete failure modes: token scope amplification across calls, server to server impersonation caused by implicit trust, and over delegation of capabilities during orchestration. I then present a practical mitigation based on capability driven design, where each request carries explicit scoped permissions, preserves the caller chain, and is verified at every hop. A prototype implementation shows how these controls block real attack paths while keeping developer experience simple. Finally, I highlight gaps in the current MCP specification and suggest extensions for safer multi agent systems.
Speakers
avatar for Aviral Sapra

Aviral Sapra

Founder, Linux foundation Decentralized Trust
I am an LFX’25 mentee of the Linux Foundation Decentralized Trust and a Web3 engineer specializing in systems development working towards my B.Tech in Computer Science from IIIT Gwalior. I have experience in developing solutions using Hyperledger Besu, and verifiable credentials... Read More →
avatar for Ryan Madhuwala

Ryan Madhuwala

Founder, Caracal
Creator and maintainer of GitMesh, a new lab under LF Decentralized Trust that transforms market surveillance into actionable Git commits. As the youngest lab leader in LFDT history, I'm building the AI infrastructure that helps developer companies decide what to build next by watching... Read More →
Friday August 14, 2026 11:30 - 11:55 KST
Orchid 1

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link