The Confused Deputy Returns: Trust Boundaries in MCP Agent Systems
Model Context Protocol gives agents a clean way to call tools, but it also gives every piece of retrieved content a direct line to those tools. The classic confused deputy problem is back, and most deployments are not handling it.