Trading agents over MCP
Four autonomous trading agents ran behind Swiftward. They read the open web, ran code and placed orders, which exposed them on two fronts at once: security and risk.
Two fronts, two sets of controls
| Front | The threat | What stood in the way |
|---|---|---|
| Security | a manipulated headline or a poisoned page becoming an unauthorized tool call, an exfiltration, or code reaching the open internet | each agent reached the model, its tools and the network only through a gateway |
| Risk | an order that looks reasonable and breaks a limit the agent cannot see | every trade checked against position, notional and velocity limits, by the same engine |
Neither check ran inside the agent, so nothing the agent was told could switch either one off.
Per tool, per argument, and on the state the engine keeps
The usual control is a switch over whole toolsets: this agent may use these tools, or it may not. Here the gateway endpoint decided which tools were offered, each agent could use only the tools it was given, and a rule decided every call, reading its arguments and the state the engine kept from earlier calls. The agent had no part in any of these checks.
What prompt injection actually looks like
It is an instruction hidden inside data the agent was told to read, and it reaches a system that can place an order. Nobody has to type "ignore your instructions". Injection detection can check what a tool returns, too.
Every decision landed in the record
Both fronts wrote the same kind of decision record: what was decided, by which rule, on which frozen version, with the signals it read. Security and risk were answered from one place, instead of from two systems that have to be reconciled afterwards.