zkMCP: Cryptographic Runtime Verification of Delegated Tool Calls for AI Agents
Sunjun Lee ⋅ Shiho Kim
Abstract
As AI agents are increasingly delegated authority to invoke external tools, recurring prompt injection attacks raise a fundamental verification challenge: *how can we determine, in real time, whether each tool call lies strictly within the delegated scope, when the verifier itself must remain sound against adversarial manipulation of the agent?* Existing approaches—behavioral verifiers (e.g., LLM-as-a-judge, sandboxed simulators) and in-service policy engines—suffer from vulnerability to injection bypasses and tight coupling with credential schemas, respectively. We propose **zkMCP**, a **cryptographic runtime verifier** that operates as a complementary safety layer: rather than inspecting agent behavior or executing service-side policies, the verifier receives a zero-knowledge proof alongside each requested action, attesting that "this action lies within the scope of the delegated credential chain," and authorizes the request only upon successful verification. The verifier's soundness derives from the knowledge-soundness of the underlying SNARK construction and is thus independent of any semantic interpretation of agent outputs, remaining sound under prompt-injection attacks. We instantiate this design for Model Context Protocol (MCP) tool call authorization, representing User $\to$ Agent delegation via SD-JWT and compiling authorization predicates into Circom circuits to produce $\sim$800-byte Groth16 proofs. To further defend against client-level bypasses in which a compromised agent forges private circuit inputs, the server independently recomputes and cross-checks the Poseidon commitment of credential values. Across four representative scenarios, no accepting proof could be produced for out-of-scope tool calls under the authenticated credential, while our reference prover rejected such calls during witness generation; proving completes in 410 ms and verification in 472 ms on commodity hardware.
Chat is not available.
Successful Page Load