Hybrid Analysis for Secure MCP Tool Use in LLM Agents
Source: https://arxiv.org/abs/2607.25297
PDF: https://arxiv.org/pdf/2607.25297v1
Content fetched: 2026-08-08T04:19:09.546162+00:00
Grounding: opencli arxiv paper metadata/abstract (arxiv_id=2607.25297)
Metadata
- Authors: Ping He, Yuexiang Xie, Yaliang Li, Shouling Ji
- Published: 2026-07-28
- Primary category: cs.CR
- Categories: cs.CR, cs.AI
- AAIF quality score: 5
中文摘要
论文围绕 MCP 工具接入后的 agent 安全风险,提出 MTGuard:把生命周期感知的静态分析和动态分析结合起来,防止 LLM agent 被诱导执行恶意或未授权工具动作摘要称该框架在多类有害工具使用场景和不同 LLM agent 上降低风险,同时保持良性任务性能
English Summary
The rapid development of large language model (LLM) agents has enabled their broad adoption across diverse real-world tasks. To standardize interactions between LLM agents and external environments, Model Context Protocol (MCP) tools have emerged as a de facto standard and have been widely integrated into these systems. However, the use of MCP tools also introduces new safety risks, as LLM agents can be induced to perform malicious or unauthorized actions. Although prior work has proposed defenses for securing tool use in LLM agents, most methods rely on static analysis, i.e., inspecting prompts and generated outputs, which limits the defense effectiveness and robustness. To address these limitations, we propose MTGuard, a hybrid analysis-based defense framework designed to safeguard the use of MCP tools in LLM agents by leveraging lifecycle-aware static-dynamic co-analysis....
Abstract
The rapid development of large language model (LLM) agents has enabled their broad adoption across diverse real-world tasks. To standardize interactions between LLM agents and external environments, Model Context Protocol (MCP) tools have emerged as a de facto standard and have been widely integrated into these systems. However, the use of MCP tools also introduces new safety risks, as LLM agents can be induced to perform malicious or unauthorized actions. Although prior work has proposed defenses for securing tool use in LLM agents, most methods rely on static analysis, i.e., inspecting prompts and generated outputs, which limits the defense effectiveness and robustness. To address these limitations, we propose MTGuard, a hybrid analysis-based defense framework designed to safeguard the use of MCP tools in LLM agents by leveraging lifecycle-aware static-dynamic co-analysis. Extensive evaluation demonstrates that MTGuard effectively mitigates multiple categories of harmful tool use across different LLM agents while maintaining performance on benign user tasks.