Loading…
Tuesday October 6, 2026 11:22 - 11:40 CEST
Tool-augmented Large Language Model (LLM) agents create a new supply-chain surface: Model Context Protocol (MCP) tools are installed like third-party packages, yet their outputs can enter the agent’s reasoning context. This enables confused-deputy risks in which attacker-controlled semantic supply-chain inputs cause otherwise benign tools to exercise legitimate authority over files, environment variables, or network-facing operations and reflect sensitive or instruction-like content into LLM-visible fields. We present SandScope, an MCP-aware audit framework that combines runtime witness detection with semantic tool profiling. SandScope executes portable tools under WebAssembly (WASM) System Interface (WASI) or drives unmodified MCP servers over standard input/output (stdio), extracts LLM-visible sinks from tool results and prompt/message fields, and reports auditable source-to-sink witnesses from environment, file, and tool-input sources while separately recording network-intent and egress evidence. Its semantic layer recovers declared capabilities from tools/list metadata and static registrations to characterize attack surface when execution is incomplete. We evaluate SandScope on controlled cross-language subjects, an evasion benchmark, and a 100-repository MCP corpus. SandScope achieves high controlled accuracy (0.941 F1) with no false positives, completes shallow dynamic scans for 38.5% of resolved real-world repositories, and extends visibility through semantic profiling to 71% of the corpus. Among recovered tools, 78.6% declare at least one security-sensitive capability. For shallow-scan successes, schema-guided exploration re-executes 94.3% and observes source-to-sink witnesses in 36.4% of re-executed repositories. These results show that SandScope provides practical, auditable evidence for MCP tool risk through controlled execution, MCP-aware sink extraction, runtime witness reporting, and semantic capability profiling.
Speakers
avatar for Zhuoran Tan

Zhuoran Tan

Security Researcher, University of Glasgow
Zhuoran (Newt) Tan is a security researcher specialising in AI/LLM security, software supply chain security, and runtime threat detection. He recently completed his PhD in Computing Science at the University of Glasgow, where his research focused on runtime observability and security... Read More →
Tuesday October 6, 2026 11:22 - 11:40 CEST
South Hall 3A

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link