Compositional trust analysis for Model Context Protocol (MCP) deployments. Detects authority paths that exist in practice but not in any individual server's manifest — where low-privilege tool output influences high-privilege tool execution without crossing a reviewed boundary.
**Breaking MCP Trust Boundaries: Cross-Server Authority Injection in Agent Toolchains** Urd is a research harness for compositional trust analysis in MCP deployments. This workshop repo demonstrates one concrete failure class: low-trust MCP output crossing through host planning context, selecting a protected record, and reappearing as a high-trust destructive tool parameter.