Technical report / Version 1
cMCP: Verifiable Policy Enforcement for AI Agent Tool Calls
OPAQUE Systems
Abstract
cMCP (Confidential MCP) proposes a gateway for policy evaluation at the Model Context Protocol tool-call boundary. The gateway evaluates Cedar policies before dispatch and emits signed records binding policy measurements, session identifiers, and tool-call evidence. Its design combines policy hashing, monotonic session sensitivity, tool-catalog pinning, and audit-chain checks. This technical report preserves software-only experiments for those mechanisms, including synthetic healthcare call traces and simulated attestation paths. The measurements illustrate behavior under the stated inputs and assumptions; they do not validate a hardware TEE, establish complete information-flow tracking, or show that every tool invocation was captured. Hardware provenance requires independent attestation appraisal and signing-key binding. Replay and omission detection additionally depend on freshness checks and an expected session or log boundary. The report distinguishes these deployment requirements from the software behavior measured here.
What this report contributes
A gateway design combining policy evaluation, session sensitivity, tool-catalog pinning, and signed tool-call records.
Evidence and limits
- The reported experiments use software-only TEE mode and synthetic traces. No hardware TEE or independent cross-organization deployment is evaluated in this report.
- The reported 11 of 16 blocked calls measures the false-discovery proportion among blocked calls. It is not the conventional false-positive rate over all negative cases.
- Replay and omission detection depend on trusted keys, freshness checks, and an expected session or log boundary. Gateway records alone do not establish complete information flow.
The source package preserves the recorded inputs and results. No new experiment run or independent replication is claimed for this edition.
Read the current specification and implementation guidance. This report describes an earlier design and evaluation; the current specification governs implementation.
Cite this report
Rishabh Poddar; Aaron Fulkerson; Imran Siddique. cMCP: Verifiable Policy Enforcement for AI Agent Tool Calls. AgenTrust technical report, version 1, 2026.
Download BibTeX / Download CITATION.cff
@techreport{agentrust2026cmcp,
title = {cMCP: Verifiable Policy Enforcement for AI Agent Tool Calls},
author = {Rishabh Poddar and Aaron Fulkerson and Imran Siddique},
institution = {AgenTrust},
year = {2026},
type = {Technical report},
note = {Version 1; not peer reviewed},
doi = {10.5281/zenodo.23001694},
url = {https://agentrust-io.com/research/cmcp/v1/}
}
Version history
Version 1, September 27, 2026: Narrows the abstract to the measured software behavior, corrects the false-discovery terminology, and adds the publication scope and patent notice.
Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.
File checksums. Published version files are retained; substantive revisions receive a new version.
Questions and corrections
Open an issue in the project repository and identify the report version and section.