Shielding MCP tool: A secure execution framework using TEE and automated trimming
Publication Type
Conference Proceeding Article
Publication Date
7-2026
Abstract
Large Language Models (LLMs) utilize the Model Context Protocol (MCP) to interact with external tools; however, the protocol’s design lacks inherent security mechanisms. This absence of security creates risks when MCP servers are deployed in untrusted environments, leaving them vulnerable to attacks that could violate authenticity, integrity, and confidentiality. To address these risks, we propose ShieldMCP, a framework to leverage hardware-based Trusted Execution Environments (TEEs) for securing MCP servers. Instead of encapsulating the entire server within a TEE, which would introduce performance overhead and an inflated trusted computing base, our approach applies fine-grained TEE protection at the tool function level, which an LLM can call to perform specific external actions such as querying a database, reading and writing files, or fetching web pages. ShieldMCP employs an automated pipeline: it first scans for tool functions in the MCP server and generates corresponding unit tests using an LLM agent. It then performs dynamic analysis to trim each function’s code. Finally, the resulting smaller artifact is packaged into a TEE and deployed with a secure, attested invocation channel. Our results show that the LLM agent achieved an average test coverage of 97%. The trimming process successfully reduced the code size by an average of 91% while maintaining functional correctness. A qualitative analysis also confirms that this architecture mitigates potential violations.
Keywords
Model context protocol, Tool function trimming, Trusted execution environment
Discipline
Information Security | Software Engineering
Research Areas
Intelligent Systems and Optimization
Publication
Proceedings of the 31st Australasian Conference, ACISP 2026, Perth, Australia, July 6-9
First Page
401
Last Page
421
ISBN
9789819230112
Identifier
10.1007/978-981-92-3012-9_17
Publisher
Springer
City or Country
Cham
Citation
HAN, Ruidong; MA, Chengyan; LIU, Ye; NIU, Yuqing; and LO, David.
Shielding MCP tool: A secure execution framework using TEE and automated trimming. (2026). Proceedings of the 31st Australasian Conference, ACISP 2026, Perth, Australia, July 6-9. 401-421.
Available at: https://ink.library.smu.edu.sg/sis_research/11314
Additional URL
https://doi.org/10.1007/978-981-92-3012-9_17