IDEAS home Printed from https://ideas.repec.org/a/gam/jftint/v18y2026i5p243-d1935157.html

The Trustworthy Model Context Protocol (MCP) Registry: An Architectural Blueprint for Cryptographic Provenance and Runtime Integrity

Author

Listed:
  • Lluis Mas

    (Department of Computer Engineering and Digital Design, University of Lleida, Jaume II 69, 25001 Lleida, Spain)

  • Jordi Vilaplana

    (Department of Computer Engineering and Digital Design, University of Lleida, Jaume II 69, 25001 Lleida, Spain)

  • Josep Rius

    (Department of Computer Engineering and Digital Design, University of Lleida, Jaume II 69, 25001 Lleida, Spain)

  • Radu Spaimoc

    (Department of Computer Engineering and Digital Design, University of Lleida, Jaume II 69, 25001 Lleida, Spain)

  • Jordi Mateo

    (Department of Computer Engineering and Digital Design, University of Lleida, Jaume II 69, 25001 Lleida, Spain)

Abstract

The Model Context Protocol (MCP) enables Large Language Models (LLMs) to act as autonomous agents that orchestrate complex workflows over distributed systems, while MCP resolves integration bottlenecks by standardizing agent-to-resource communication. Its current registry relies on an unverified pointer architecture, exposing agentic workflows to supply chain poisoning and dynamic capability mutation (“Rug Pull”) attacks. This paper identifies this gap and proposes a three-layer architectural framework for a Trustworthy MCP Registry. The novelty of our contribution lies not in the individual standards employed (RFC 8615, Sigstore, and JCS/JWS are established technologies), but in their specific composition to address MCP’s unique runtime security requirements: (1) RFC 8615 Well-Known URIs for decentralized server discovery and domain-bound identity; (2) Sigstore Keyless signing to bind server artifacts to audited CI/CD environments without managing long-lived keys; and (3) JSON Canonicalization Scheme (RFC 8785) combined with JWS to provide deterministic, per-message integrity verification of live capability updates. We present a prototype implementation and an experimental evaluation conducted in a controlled, synthetic environment. Results indicate that the cryptographic overhead averages 0.61 ms per signing operation and that the Layer 3 mechanism correctly rejects all 100 simulated Rug Pull attempts, as expected by construction, since an attacker without the server’s private key cannot produce a valid signature. These findings suggest that the proposed approach is feasible and warrants further evaluation in real-world deployment settings.

Suggested Citation

  • Lluis Mas & Jordi Vilaplana & Josep Rius & Radu Spaimoc & Jordi Mateo, 2026. "The Trustworthy Model Context Protocol (MCP) Registry: An Architectural Blueprint for Cryptographic Provenance and Runtime Integrity," Future Internet, MDPI, vol. 18(5), pages 1-26, May.
  • Handle: RePEc:gam:jftint:v:18:y:2026:i:5:p:243-:d:1935157
    as

    Download full text from publisher

    File URL: https://www.mdpi.com/1999-5903/18/5/243/pdf
    Download Restriction: no

    File URL: https://www.mdpi.com/1999-5903/18/5/243/
    Download Restriction: no
    ---><---

    More about this item

    Keywords

    ;
    ;
    ;
    ;
    ;

    Statistics

    Access and download statistics

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:gam:jftint:v:18:y:2026:i:5:p:243-:d:1935157. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    We have no bibliographic references for this item. You can help adding them by using this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: MDPI Indexing Manager The email address of this maintainer does not seem to be valid anymore. Please ask MDPI Indexing Manager to update the entry or send us the correct address (email available below). General contact details of provider: https://www.mdpi.com .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.