Before the Provider Call: Enforcing Exact-Term Authorization for State-Changing Tool Actions
Abstract
This working paper examines a narrow but consequential WebMCP question: what happens between an AI agent proposing a state-changing action and a provider executing it? Across a controlled 576-run study spanning Claude, Gemini, and GPT, the baseline condition produced 165 unauthorized provider executions among 175 attempted state-changing calls. With a transaction-specific pre-provider authorization intervention enabled, 200 unauthorized attempts were blocked, 35 authorized attempts executed, and no unauthorized execution was observed across 235 attempts. In this frozen experimental environment, execution-boundary controls changed whether unauthorized model-generated transactions reached the provider. The study does not test Chrome’s origin-trial implementation, live commerce, prompt-injection resistance, semantic alignment with user intent, or universal WebMCP compatibility. Outcomes were determined from preserved execution records and provider-side evidence rather than model narration. The paper includes the experimental matrix, model and family level results, integrity checks, invalid-study disclosure, limitations, and claim boundaries. Proprietary implementation details and nonpublic study materials are not included.
// Source
Authors: Kristina Baldovino