Agents, MCP, and retrieval
Keep retrieved content, model output, tool authority, and user consent separate throughout an AI-assisted workflow.
This is the complete downloadable file. Open plain text ↗
---
name: ai-agent
description: "Keep retrieved content, model output, tool authority, and user consent separate throughout an AI-assisted workflow."
---
# Agents, MCP, and retrieval
Keep retrieved content, model output, tool authority, and user consent separate throughout an AI-assisted workflow.
Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.
## Bring to the review
- Tool definitions and granted scopes
- Retrieval permissions and provenance metadata
- Human approval and audit requirements
## Review guide
### 1. Model authority separately
Document what the model may suggest, what a tool may do, and which identity authorizes the tool invocation.
### 2. Review retrieval boundaries
Require authorization and provenance checks before tenant or sensitive documents reach context.
### 3. Validate before action
Make tools independently validate typed arguments, resource scope, and policy rather than trusting generated instructions.
### 4. Make consent progressive
Present meaningful scope at approval time and retain an audit trail for sensitive operations.
## What to produce
- Authority and consent map
- Retrieval boundary policy
- Tool validation contract
## Common mistakes
- Granting a broad token to a narrow task
- Treating retrieved text as instructions
- Equating a model error with an authorized security impact
## Reading and source context
### Resources
- [MCP scope selection: progressive consent and accumulated authority](https://vulns.co/research/resources/mcp-progressive-scope-authority/)
- [OWASP LLM08:2025: retrieval permissions and knowledge provenance](https://vulns.co/research/resources/owasp-rag-retrieval-permission-boundaries/)
- [OWASP LLM05:2025: generated-output consumer trust](https://vulns.co/research/resources/owasp-llm-output-consumer-trust/)
### Diagrams
- [Retrieved content is data, not authority](https://vulns.co/research/diagrams/ai-content-authority-separation/)
### Reports
- [Gemini Enterprise connected-content trust failure allowed persistent-memory modification](https://vulns.co/research/reports/google-gemini-enterprise-connected-content-memory-integrity-2026/)
- [Gemini-to-Colab rendering boundary exposed Workspace data](https://vulns.co/research/reports/google-gemini-colab-rendering-boundary-2025/)
## Provenance
Editorial guide by vulns.co / GK Data. Updated 2026-10-11.
Library snapshot: 2026-10-04; commit d5550c7891119cf1379e235721541c947850a3b3.
The guide is an editorial synthesis. Linked records preserve their own sources and review dates.
Reader: https://vulns.co/skills/ai-agent/
The review
What to look for
Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.
Model authority separately
Document what the model may suggest, what a tool may do, and which identity authorizes the tool invocation.
Review retrieval boundaries
Require authorization and provenance checks before tenant or sensitive documents reach context.
Validate before action
Make tools independently validate typed arguments, resource scope, and policy rather than trusting generated instructions.
Make consent progressive
Present meaningful scope at approval time and retain an audit trail for sensitive operations.
What to produce
- Authority and consent map
- Retrieval boundary policy
- Tool validation contract
Common mistakes
- Granting a broad token to a narrow task
- Treating retrieved text as instructions
- Equating a model error with an authorized security impact
Continue the study
Reading & source context
Editorial notes above connect these references. Open each record for its original source and review date.
Visual models
Connected disclosures
From the field toolkit
Guide by GK Data · Research snapshot 2026-10-04.
Sources and review dates are preserved in the library provenance.