Technical report / Version 2

cMCP: Verifiable Policy Enforcement for AI Agent Tool Calls

Rishabh Poddar, Aaron Fulkerson, Imran Siddique

OPAQUE Systems

October 1, 2026Not peer reviewedPatent Pending

Abstract

cMCP (Confidential MCP) proposes a gateway for policy evaluation at the Model Context Protocol tool-call boundary. The gateway evaluates Cedar policies before dispatch and emits signed records binding policy measurements, session identifiers, and tool-call evidence. Its design combines policy hashing, monotonic session sensitivity, tool-catalog pinning, and audit-chain checks. This technical report preserves software-only experiments for those mechanisms, including synthetic healthcare call traces and simulated attestation paths. The measurements illustrate behavior under the stated inputs and assumptions; they do not validate a hardware TEE, establish complete information-flow tracking, or show that every tool invocation was captured. Hardware provenance requires independent attestation appraisal and signing-key binding. Replay and omission detection additionally depend on freshness checks and an expected session or log boundary. The report distinguishes these deployment requirements from the software behavior measured here.

What this report contributes

A gateway design combining policy evaluation, session sensitivity, tool-catalog pinning, and signed tool-call records.

Evidence and limits

The source package preserves the recorded inputs and results. Every experiment was rerun on October 1, 2026 at the measured revision 6f12cce and at current main; correctness results are unchanged. No independent replication is claimed.

Read the current specification and implementation guidance. This report describes an earlier design and evaluation; the current specification governs implementation.

Cite this report

Rishabh Poddar; Aaron Fulkerson; Imran Siddique. cMCP: Verifiable Policy Enforcement for AI Agent Tool Calls. AgenTrust technical report, version 2, 2026.

Download BibTeX / Download CITATION.cff

@techreport{agentrust2026cmcp,
  title = {cMCP: Verifiable Policy Enforcement for AI Agent Tool Calls},
  author = {Rishabh Poddar and Aaron Fulkerson and Imran Siddique},
  institution = {AgenTrust},
  year = {2026},
  type = {Technical report},
  note = {Version 2; not peer reviewed},
  doi = {10.5281/zenodo.23091276},
  url = {https://agentrust-io.com/research/cmcp/v2/}
}

Version history

Version 2, October 1, 2026: Corrects the REPORT_DATA size, the session-claim nonce, when the catalog check runs, trial counts, two citations and two performance figures, names the measured revision and its advisories, and restores bold and italic type. Correctness results unchanged.

Version 1, September 27, 2026: Narrows the abstract to the measured software behavior, corrects the false-discovery terminology, and adds the publication scope and patent notice.

Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.

File checksums. Published version files are retained; substantive revisions receive a new version.

Questions and corrections

Open an issue in the project repository and identify the report version and section.