Published August 4, 2026 | Version v1.0.0

Before the Provider Call: Enforcing Exact-Term Authorization for State-Changing Tool Actions

Authors/Creators

Description

This working paper examines a narrow but consequential WebMCP question: what happens between an AI agent proposing a state-changing action and a provider executing it?

Across a controlled 576-run study spanning Claude, Gemini, and GPT, the baseline condition produced 165 unauthorized provider executions among 175 attempted state-changing calls. With a transaction-specific pre-provider authorization intervention enabled, 200 unauthorized attempts were blocked, 35 authorized attempts executed, and no unauthorized execution was observed across 235 attempts.

In this frozen experimental environment, execution-boundary controls changed whether unauthorized model-generated transactions reached the provider. The study does not test Chrome’s origin-trial implementation, live commerce, prompt-injection resistance, semantic alignment with user intent, or universal WebMCP compatibility. Outcomes were determined from preserved execution records and provider-side evidence rather than model narration.

The paper includes the experimental matrix, model and family level results, integrity checks, invalid-study disclosure, limitations, and claim boundaries. Proprietary implementation details and nonpublic study materials are not included.

Files

Files (172.3 kB)

Name Size Download all
md5:b29c6d88d20da527bb3878f479812f14
172.3 kB Download