Back to feed
Dev.to
Dev.to
7/14/2026
The MCP Confused Deputy: Provenance Gaps, Instruction Injection, and DNS Rebinding in the Model Context Protocol

The MCP Confused Deputy: Provenance Gaps, Instruction Injection, and DNS Rebinding in the Model Context Protocol

Short summary

A deep security analysis of the Model Context Protocol's confused deputy problem: MCP tool results carry no cryptographic provenance, so models cannot distinguish trusted server output from attacker-controlled content. The article details how the official Anthropic MCP fetch server converts web pages to Markdown without sanitization, enabling indirect prompt injection, and outlines DNS rebinding as a related attack vector. ToolAnnotations are advisory only with no verifiable binding to actual behavior.

  • MCP tool results lack cryptographic provenance — models can't distinguish trusted vs attacker-controlled content
  • The official Anthropic MCP fetch server passes unsanitized web content into model context, enabling indirect prompt injection
  • ToolAnnotations (readOnlyHint, destructiveHint) are advisory with no security enforcement

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more