Policy enforcement verification, cross-vendor attested registries, and privacy-preserving auditability in MCP

Investigate and develop formal verification methods for enforcing safety and security policies in MCP-based agent workflows; design cross-vendor interoperable attested registries for MCP tools and servers; and create privacy-preserving auditability mechanisms that provide verifiable provenance and compliance evidence without exposing sensitive data.

Background

After outlining a defense-in-depth architecture for MCP, the paper identifies remaining research gaps that hinder trustworthy deployment at scale.

The authors specifically point to the need for provable policy enforcement around agent actions, interoperable registries that can attest tool integrity across vendors, and auditability solutions that balance transparency with privacy.

References

However, significant research challenges remain. Questions around formal verification of policy enforcement, cross-vendor interoperability of attested registries, and privacy-preserving auditability are still open areas of study.

Systematization of Knowledge: Security and Safety in the Model Context Protocol Ecosystem  (2512.08290 - Gaire et al., 9 Dec 2025) in Section 6 Synthesis and Outlook

Another open question is how external auditors can independently verify selected evidence without exposing sensitive agent communications, risk records, mitigation details, or business data.

An Evidence Model for Agentic Processes: Evidence Claims, Trust Assumptions, and Policy Assessment  (2609.08481 - Brömme, 8 Sep 2026) in Section 9, “Limitations and Future Work”

These approaches are early and carry open questions (e.g., registry governance, attestation cost, and the circularity of using one trust system to bootstrap another), and we present them as a promising but unsettled direction rather than a solution.

When Agents Act on Web3: An Attack-Surface Survey of MCP, Skills, and Tool Calling  (2608.17275 - Karanjai et al., 18 Aug 2026) in Section 3.2, “Blockchain-based defenses”