vulns.co
/
GKData.io MCP
ID / Identity

Agents, MCP, and retrieval

Keep retrieved content, model output, tool authority, and user consent separate throughout an AI-assisted workflow.

Guide 08 / 154 review notesUpdated 2026-10-11

The review

What to look for

Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.

  1. Model authority separately

    Document what the model may suggest, what a tool may do, and which identity authorizes the tool invocation.

  2. Review retrieval boundaries

    Require authorization and provenance checks before tenant or sensitive documents reach context.

  3. Validate before action

    Make tools independently validate typed arguments, resource scope, and policy rather than trusting generated instructions.

  4. Make consent progressive

    Present meaningful scope at approval time and retain an audit trail for sensitive operations.

What to produce

  • Authority and consent map
  • Retrieval boundary policy
  • Tool validation contract

Common mistakes

  • Granting a broad token to a narrow task
  • Treating retrieved text as instructions
  • Equating a model error with an authorized security impact

Continue the study

Reading & source context

Editorial notes above connect these references. Open each record for its original source and review date.

Visual models

Connected disclosures

From the field toolkit

Guide by GK Data · Research snapshot 2026-10-04.
Sources and review dates are preserved in the library provenance.

Next skillCI and dependency trust →