<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[BiriyaniBot]]></title><description><![CDATA[BiriyaniBot]]></description><link>https://biriyanibot.hashnode.dev</link><generator>RSS for Node</generator><lastBuildDate>Sat, 10 Oct 2026 16:06:58 GMT</lastBuildDate><atom:link href="https://biriyanibot.hashnode.dev/rss.xml" rel="self" type="application/rss+xml"/><language><![CDATA[en]]></language><ttl>60</ttl><item><title><![CDATA[Old Problem, New Protocol: Why the Confused Deputy Still Matters in AI]]></title><description><![CDATA[The Model Context Protocol (MCP) is an open standard that lets AI applications (clients) connect to external tools, systems, and data sources (servers) through a single, uniform interface—often described as “USB‑C for AI.” It solves the painful N×M i...]]></description><link>https://biriyanibot.hashnode.dev/old-problem-new-protocol-why-the-confused-deputy-still-matters-in-ai</link><guid isPermaLink="true">https://biriyanibot.hashnode.dev/old-problem-new-protocol-why-the-confused-deputy-still-matters-in-ai</guid><category><![CDATA[AI]]></category><category><![CDATA[mcp]]></category><category><![CDATA[oauth]]></category><category><![CDATA[Model Context Protocol]]></category><category><![CDATA[integration]]></category><category><![CDATA[vulnerability]]></category><category><![CDATA[Security]]></category><category><![CDATA[#securitybestpractices ]]></category><category><![CDATA[ai security]]></category><dc:creator><![CDATA[Sushobhan Mondal]]></dc:creator><pubDate>Wed, 11 Feb 2026 15:42:40 GMT</pubDate><enclosure url="https://cdn.hashnode.com/res/hashnode/image/upload/v1770823655548/a43ba1a6-19f0-403b-926e-9894da44a2cf.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The Model Context Protocol (MCP) is an open standard that lets AI applications (clients) connect to external tools, systems, and data sources (servers) through a single, uniform interface—often described as “USB‑C for AI.” It solves the painful N×M integration problem by decoupling AI apps from the myriad services they need to use, thereby shrinking bespoke glue code and enabling a shared ecosystem of integrations.</p>
<p>This power—letting LLMs call tools and access real data—amplifies risk. Among the most important risks is the confused deputy problem, a decades-old vulnerability pattern where a more-privileged component is tricked into misusing its own authority on behalf of a less-privileged requester. It is not unique to MCP, but MCP’s architecture makes it particularly salient if you deploy servers that act as OAuth-backed proxies to third-party APIs without enforcing per-client consent.</p>
<p>This article explains MCP fundamentals, why the confused deputy risk is pronounced in MCP deployments and how to design defenses without sacrificing performance or developer velocity.</p>
<h2 id="heading-why-is-mcp-in-the-news"><strong>Why is MCP in the news?</strong></h2>
<p>MCP is an open protocol, governed neutrally, that standardizes the way AI applications discover and utilize tools, access resources, and reuse prompts provided by MCP servers via transports like stdio and HTTP. Official SDKs are available for major programming languages, and the specification is continuously evolving to include features such as asynchronous operations, server identity, and official extensions. Leading vendors in the ecosystem, including Anthropic, Microsoft/GitHub, OpenAI, and Google, are supporting MCP to minimize fragmentation and facilitate portable, governed connections between AI assistants and the necessary tools and data.</p>
<p><strong>Solving N×M</strong></p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1770764330458/aa1ce45c-6b16-4194-93c0-d1aeeadb94cb.png" alt class="image--center mx-auto" /></p>
<p>Before MCP, combining N tools with M AI interfaces needed N×M custom connectors. MCP simplifies this to N + M: each tool sets up a server once, and each AI app sets up a client once. This is like the “USB‑C for AI” analogy—one port, multiple devices.</p>
<h2 id="heading-what-are-the-security-risks"><strong>What are the Security Risks?</strong></h2>
<p>MCP enables LLM‑driven tool execution and context access across process and network boundaries. That creates an attack surface that includes prompt/tool injection, identity/authorization gaps, supply‑chain risk from third‑party servers, and—our focus here—confused deputy when a server acts as a proxy to an OAuth‑protected API. The spec’s Security Best Practices explicitly calls out this risk and outlines mitigations.</p>
<h3 id="heading-the-confused-deputy-problem"><strong>The Confused Deputy Problem</strong></h3>
<p>A confused deputy occurs when a more‑privileged component (the “deputy”) is tricked into misusing its own authority to perform an action requested by a less‑privileged party. The attacker does not gain new privileges; instead, they induce the deputy to act with the deputy’s privileges. This vulnerability predates MCP and is well known in OS, compilers, cloud IAM, API gateways, and OAuth ecosystems.</p>
<p><strong>Why MCP makes it pronounced</strong></p>
<p>MCP servers frequently encapsulate powerful tool capabilities and sometimes forward those calls to third‑party APIs using OAuth. If a server acts as a proxy and uses a static OAuth <code>client_id</code> toward the third‑party authorization server—and does not enforce per‑client consent—then prior consent for one user can be reused silently for another, causing the proxy to act as a confused deputy.</p>
<p><em>Key nuance: In MCP documentation, an “MCP proxy” is not a separate protocol role; it’s a type of MCP server that forwards requests to external APIs and holds OAuth credentials. Every MCP proxy is an MCP server, but not every MCP server is a proxy.</em></p>
<p>A proxy is simply an MCP server whose <em>implementation</em> forwards requests to a third‑party API and holds OAuth state. Thus, clients still call servers directly—but a given server may behave as a proxy internally. The confused‑deputy risk is specific to such proxy‑style servers that do not perform per‑client consent enforcement and rely on static OAuth client identities.</p>
<h3 id="heading-how-the-confused-deputy-emerges-in-mcp"><strong>How the Confused Deputy Emerges in MCP</strong></h3>
<p>The MCP security guidance describes a concrete flow: an MCP server acting as a proxy uses a static client ID against a third‑party OAuth server. Once a user (User A) grants consent, the third‑party server may cache that consent (e.g., via cookies/sessions) for the proxy’s <code>client_id</code>. If the proxy doesn’t enforce per‑client consent internally, a different MCP client (User B) can invoke the proxy, which then reuses the already‑granted authority to perform privileged actions—no new user consent required. That’s the deputy (proxy) misusing its own privileges.</p>
<p>Key points:</p>
<ul>
<li><p>The attacker does not escalate their own privilege.</p>
</li>
<li><p>The proxy performs the action using its credentials (or tokens derived from its static client identity).</p>
</li>
<li><p>The third‑party API sees the same OAuth <code>client_id</code> and trusts the prior consent.</p>
</li>
<li><p>Result: cross‑user authorization leakage, i.e., confused deputy.</p>
</li>
</ul>
<p><strong>Illustrative Flows</strong></p>
<p><strong>Baseline (legit first‑time consent)</strong>: User A - a valid user - approves scopes; third‑party binds consent to the proxy’s <code>client_id</code>.</p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1770757919070/8d13fe58-cbb5-49c1-9282-48e0b2c390ea.png" alt class="image--center mx-auto" /></p>
<p><strong>Vulnerable flow</strong>: (confused deputy): User B calls the same proxy; the proxy reuses consent for its static <code>client_id</code>; third‑party skips consent; privileged data/actions flow to B.</p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1770758028329/84fb5cae-f560-4a54-a609-522f72061ab7.png" alt class="image--center mx-auto" /></p>
<p><em>Key nuance: A Confused Deputy problem is not Privilege Escalation. In privilege escalation, the attacker gains higher privileges (e.g., user to admin). In a confused deputy scenario, no new privileges are gained; instead, a privileged deputy is tricked into using its authority for the attacker.</em></p>
<h3 id="heading-how-to-mitigate-the-confused-deputy-problem-in-mcp"><strong>How to mitigate the Confused Deputy problem in MCP</strong></h3>
<ol>
<li><p><strong>Per‑client consent enforcement (a must‑have).</strong><br /> Make sure each user has their own consent record. If a user hasn’t approved access—or needs a new scope—ask again. Never reuse another user’s consent.</p>
</li>
<li><p><strong>Bind identity end‑to‑end.</strong><br /> Every request should include a verifiable user identity (OIDC/Entra, etc.). The MCP client, proxy, and the upstream API should all know who the request is for. Tokens and actions must map to the actual user, not the proxy.</p>
</li>
<li><p><strong>Avoid static client identity where possible.</strong><br /> Prefer dynamic client registration, resource indicators, PKCE, and user‑bound tokens supported by the upstream provider—per MCP authorization guidance.</p>
</li>
<li><p><strong>Constrain blast radius.</strong><br /> Run MCP proxy servers in isolated environments. Control egress, limit what each tool is allowed to do, and set rate limits. Treat every tool description as untrusted input.</p>
</li>
<li><p><strong>Strong audit and observability.</strong><br /> Log who requested what, which identity was used upstream, what scope was exercised, and where data went. Feed into SIEM to detect anomalies.</p>
</li>
</ol>
<p><strong>Hardened flow:</strong> The proxy enforces per‑client consent and binds tokens to the initiating user (e.g., OIDC/OAuth 2.1 patterns), preventing cross‑user reuse.</p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1770758937329/f7ee3a9e-683f-426d-b138-7c0c9362f723.png" alt class="image--center mx-auto" /></p>
<p>The MCP Security Best Practices explicitly documents the confused‑deputy risk pattern for proxy servers and describes required mitigations. Besides, security communities already treat confused deputy as a first‑class risk; MCP simply inherits this reality as it bridges untrusted LLM behavior with privileged tools. So this is not “just” a theoretical problem.</p>
<h2 id="heading-key-takeaways"><strong>Key Takeaways</strong></h2>
<ul>
<li><p>MCP matters because it standardizes how AI apps use tools and data—solving N×M integration, reducing glue code, and enabling a shared ecosystem.</p>
</li>
<li><p>However, it comes with security risks like the confused deputy problem which is amplified when MCP servers proxy to OAuth‑protected APIs without per‑client consent.</p>
</li>
<li><p>Mitigate it with per‑client consent, identity binding, dynamic registration/PKCE/resource indicators, and strong audit/egress controls.</p>
</li>
</ul>
<p><strong>Acknowledgements / Sources</strong></p>
<ul>
<li><p>MCP Fundamentals &amp; Spec: Anthropic announcement; official docs/spec; GitHub repo. <a target="_blank" href="https://www.permit.io/blog/the-ultimate-guide-to-mcp-auth">[permit.io]</a>, <a target="_blank" href="https://modelcontextprotocol.io/specification/2025-06-18/basic/authorization">[modelcontextprotocol.io]</a>, <a target="_blank" href="https://arstechnica.com/information-technology/2025/04/mcp-the-new-usb-c-for-ai-thats-bringing-fierce-rivals-together/">[arstechnica.com]</a>, <a target="_blank" href="https://www.anthropic.com/news/donating-the-model-context-protocol-and-establishing-of-the-agentic-ai-foundation">[anthropic.com]</a></p>
</li>
<li><p>Ecosystem Momentum: Microsoft/GitHub announcements; industry coverage. <a target="_blank" href="https://docs.langchain.com/oss/python/langchain/mcp">[docs.langchain.com]</a>, <a target="_blank" href="https://spknowledge.com/2025/06/06/configure-mcp-servers-on-vscode-cursor-claude-desktop/">[spknowledge.com]</a></p>
</li>
<li><p>Security Best Practices &amp; Confused Deputy: Official MCP security guidance. <a target="_blank" href="https://www.cdata.com/blog/2026-year-enterprise-ready-mcp-adoption">[cdata.com]</a></p>
</li>
</ul>
]]></content:encoded></item></channel></rss>