MCP Security

MCP security is the practice of securing Model Context Protocol implementations, addressing tool poisoning, over-broad permission scopes, credential handling, and supply chain risk in the MCP ecosystem.

Why MCP Introduces Its Own Security Category

The Model Context Protocol (MCP) gives AI agents a standardized way to connect to tools, data sources, and services. That standardization is powerful, but it also creates new categories of attack surface.

Common MCP-specific concerns include tool poisoning, in which a malicious MCP server injects instructions into the tool descriptions the agent reads, over-broad OAuth scopes granted at MCP connection time, credential and token handling within the MCP client environment, and supply chain risk from open-source MCP servers of varying quality and trustworthiness.

MCP and Agent Blast Radius

MCP dramatically expands what an agent can do. It also expands the blast radius if the agent is compromised. A single agent connected to a set of MCP servers might have effective access to email, calendars, drives, code repositories, and business applications simultaneously. MCP security is largely about controlling that blast radius.

Defenses in MCP Security

Emerging MCP security practices include vetting MCP servers before connection, applying narrow permission scoping at the MCP layer, monitoring MCP traffic for anomalous tool usage, and treating MCP servers as third-party dependencies subject to AI TPRM processes.

Related Terms

Full AI Visibility. Full Control. One Connected Platform.

Enterprise AI is expanding faster than most governance programs can track. Kovrr connects every AI signal across browser, endpoint, network, identity, and vendor systems into a single platform so security, governance, and risk teams work from the same evidence.