Retrieved article excerpt
Open article · Retrieved 2026-09-17T08:21:59.018603+00:00
# Computer Science > Cryptography and Security
**arXiv:2609.18217** (cs)
[Submitted on 16 Sep 2026]
# Title:Measuring and Exploiting Implicit Trust in LLM Tool-Calling Pipelines
Authors:[Murali Ediga](https://arxiv.org/search/cs?searchtype=author&query=Ediga,+M), [Sudipta Chattopadhyay](https://arxiv.org/search/cs?searchtype=author&query=Chattopadhyay,+S)
View a PDF of the paper titled Measuring and Exploiting Implicit Trust in LLM Tool-Calling Pipelines, by Murali Ediga and Sudipta Chattopadhyay
[View PDF](https://arxiv.org/pdf/2609.18217)
[HTML (experimental)](https://arxiv.org/html/2609.18217v1)
> Abstract:The Model Context Protocol (MCP) enables LLMs to invoke external tools, but every tool interaction exposes the model to attacker-controlled text through multiple input channels (tool descriptions, tool results, sampling messages) that share a single context window without privilege separation. In this paper, we present a framework to measure the trust profile of an arbitrary LLM based on a variety of payload framings sent through different channels. Following this assessment, we devise cross-channel fragmentation attacks that distribute seemingly benign payloads across two or three channels; no individual channel carries a complete injection, yet the LLM compiles the fragments into credential exfiltration. We evaluated our attacks across 12 frontier models, three production clients, and six payloads, totalling over 15,000 trials. Our evaluation reveals that cross-channel attacks are an unexplored attack surface: models that fully resist single-channel injection (0% compliance) exfiltrate sensitive data at up to 100% under two-channel fragmentation (e.g., GPT-4o, Llama 70B, Composer 2, Haiku 4.5). We further demonstrate value-aligned exploitation, where a tool's stated purpose requires the data the attacker targets, and a sampling system prompt override that injects persistent instructions via VS Code's MCP implementation. Finally, we evaluated our attacks against seven third-party MCP security tools and three prompt-based defenses. All tools failed to detect fragmented payloads, and prompt defenses proved model-specific rather than universal.
| | |
| --- | --- |
| Subjects: | Cryptography and Security (cs.CR) |
| Cite as: | [arXiv:2609.18217](https://arxiv.org/abs/2609.18217) [cs.CR] |
| | (or [arXiv:2609.18217v1](https://arxiv.org/abs/2609.18217v1) [cs.CR] for this version) |
| | <https://doi.org/10.48550/arXiv.2609.18217> Focus to learn more arXiv-issued DOI via DataCite (pending registration) |
## Submission history
From: Sudipta Chattopadhyay [[view email](https://arxiv.org/show-email/0c8efabe/2609.18217)]
**[v1]**
Wed, 16 Sep 2026 06:47:10 UTC (2,079 KB)
Full-text links:
## Access Paper:
View a PDF of the paper titled Measuring and Exploiting Implicit Trust in LLM Tool-Calling Pipelines, by Murali Ediga and Sudipta Chattopadhyay
- [View PDF](https://arxiv.org/pdf/2609.18217)
- [HTML (experimental)](https://arxiv.org/html/2609.18217v1)
- [TeX Source](https://arxiv.org/src/2609.18217)
[license icon](http://creativecommons.org/licenses/by-nc-nd/4.0/ "Rights to this article")
### Current browse context:
cs.CR
[< prev](https://arxiv.org/prevnext?id=2609.18217&function=prev&context=cs.CR "previous in cs.CR (accesskey p)")
|
[next >](https://arxiv.org/prevnext?id=2609.18217&function=next&context=cs.CR "next in cs.CR (accesskey n)")
[new](https://arxiv.org/list/cs.CR/new)
|
[recent](https://arxiv.org/list/cs.CR/recent)
| [2026-09](https://arxiv.org/list/cs.CR/2026-09)
Change to browse by:
[cs](https://arxiv.org/abs/2609.18217?context=cs)
### References & Citations
- [NASA ADS](https://ui.adsabs.harvard.edu/abs/arXiv:2609.18217)
- [Google Scholar](https://scholar.google.com/scholar_lookup?arxiv_id=2609.18217)
- [Semantic Scholar](https://api.semanticscholar.org/arXiv:2609.18217)
export BibTeX citation
Loading...
## BibTeX formatted citation
×
loading...
Data provided by:
### Bookmark
[BibSonomy](http://www.bibsonomy.org/BibtexHandler?requTask=upload&url=https://arxiv.org/abs/2609.18217&description=Measuring and Exploiting Implicit Trust in LLM Tool-Calling Pipelines "Bookmark on BibSonomy")
[Reddit](https://reddit.com/submit?url=https://arxiv.org/abs/2609.18217&title=Measuring and Exploiting Implicit Trust in LLM Tool-Calling Pipelines "Bookmark on Reddit")
Bibliographic Tools
# Bibliographic and Citation Tools
Bibliographic Explorer Toggle
Bibliographic Explorer *([What is the Explorer?](https://info.arxiv.org/labs/showcase.html#arxiv-bibliographic-explorer))*
Connected Papers Toggle
Connected Papers *([What is Connected Papers?](https://www.connectedpapers.com/about))*
Litmaps Toggle
Litmaps *([What is Litmaps?](https://www.litmaps.co/))*
scite.ai Toggle
scite Smart Citations *([What are Smart Citations?](https://www.scite.ai/))*
Code, Data, Media
# Code, Data and Media Associated with this Article
alphaXiv Toggle
alphaXiv *([What is alphaXiv?](https://alphaxiv.org/))*
Links to Code Toggle
CatalyzeX Code Finder for Papers *([What is CatalyzeX?](https://www.catalyzex.com))*
DagsHub Toggle
DagsHub *([What is DagsHub?](https://dagshub.com/))*
GotitPub Toggle
Gotit.pub *([What is GotitPub?](http://gotit.pub/faq))*
Huggingface Toggle
Hugging Face *([What is Huggingface?](https://huggingface.co/huggingface))*
ScienceCast Toggle
ScienceCast *([What is ScienceCast?](https://sciencecast.org/welcome))*
Demos
# Demos
Replicate Toggle
Replicate *([What is Replicate?](https://replicate.com/docs/arxiv/about))*
Spaces Toggle
Hugging Face Spaces *([What is Spaces?](https://huggingface.co/docs/hub/spaces))*
Spaces Toggle
TXYZ.AI *([What is TXYZ.AI?](https://txyz.ai))*
Related Papers
# Recommenders and Search Tools
Link to Influence Flower
Influence Flower *([What are Influence Flowers?](https://influencemap.cmlab.dev/))*
Core recommender toggle
CORE Recommender *([What is CORE?](https://core.ac.uk/services/recommender))*
- Author
- Venue
- Institution
- Topic
About arXivLabs
# arXivLabs: experimental projects with community collaborators
arXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website.
Both individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them.
Have an idea for a project that will add value for arXiv's community? [**Learn more about arXivLabs**](https://info.arxiv.org/labs/index.html).
[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2609.18217) |
Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))