ScopeGuard: Mitigating Goal Drift and Confused Deputy Attacks in MCP Agent Pipelines

This paper presents ScopeGuard, a middleware-based security architecture for Model Context Protocol (MCP) agent pipelines that jointly addresses goal drift and confused-deputy attacks. ScopeGuard mediates planner-generated tasks before execution using four complementary checks: semantic intent alignment, provenance verification, least-privilege permission validation, and prompt-injection detection. The prototype is evaluated on 831 labeled tasks, including real goal-drift trajectories and benchmark injection and confused-deputy attacks, demonstrating 80.6% detection of real goal drift and 100% detection of the evaluated injection and confused-deputy cases.