Dev.to
7/14/2026

The MCP Confused Deputy: Provenance Gaps, Instruction Injection, and DNS Rebinding in the Model Context Protocol
Short summary
A deep security analysis of the Model Context Protocol's confused deputy problem: MCP tool results carry no cryptographic provenance, so models cannot distinguish trusted server output from attacker-controlled content. The article details how the official Anthropic MCP fetch server converts web pages to Markdown without sanitization, enabling indirect prompt injection, and outlines DNS rebinding as a related attack vector. ToolAnnotations are advisory only with no verifiable binding to actual behavior.
- •MCP tool results lack cryptographic provenance — models can't distinguish trusted vs attacker-controlled content
- •The official Anthropic MCP fetch server passes unsanitized web content into model context, enabling indirect prompt injection
- •ToolAnnotations (readOnlyHint, destructiveHint) are advisory with no security enforcement
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



