Formal verification of MCP workflows
Establish formal verification models and methods for Model Context Protocol (MCP)-based workflows that combine natural-language prompts, JSON-RPC tool discovery and execution, and host policy checks, proving properties such as non-execution of unauthorized commands and resistance to confused-deputy scenarios in agentic AI systems.
References
Formal verification in this context remains largely open.
— Systematization of Knowledge: Security and Safety in the Model Context Protocol Ecosystem
(2512.08290 - Gaire et al., 9 Dec 2025) in Section 7.1 Formal Verification of MCP Protocols
The unsolved problem is verifying not who authored a description but whether it is honest: whether a tool's declared behavior matches its actual behavior.
— When Agents Act on Web3: An Attack-Surface Survey of MCP, Skills, and Tool Calling
(2608.17275 - Karanjai et al., 18 Aug 2026) in Section 4.1, “Semantic integrity of tool descriptions”