Multi-Step Tool-Call Chain Attacks in MCP Agent Systems (ChainWatch Detection Research)
lowAgentProtocol VulnerabilityThis is defensive academic research, not an active exploit or new vulnerability disclosure. The paper proposes ChainWatch, a detection framework using a kill-chain model and Hidden Markov Models to spot malicious sequences of otherwise-benign MCP tool calls that evade per-call security checks. It confirms a known class of risk (composable multi-step attacks in MCP agent systems) but the artifact itself is a defense, so severity is low from a threat-alert perspective.
Updated Jul 23, 2026