Guide · Checked against vendor sites, September 2026
MCP security: how to control what MCP servers let AI agents do
The verdict
MCP security means knowing which MCP servers your agents connect to, limiting what each one can do, and checking tool calls before they run. The MCP specification itself warns that local MCP servers run with the same privileges as the client, so an unvetted server on a laptop can execute commands and read data with the user's access.
Part of the University: Basics track
What is MCP?
The Model Context Protocol is an open-source standard for connecting AI applications to external systems. Its documentation describes it as "like a USB-C port for AI applications": one way for an AI app such as Claude, ChatGPT, Visual Studio Code or Cursor to connect to data sources, tools and workflows. An MCP server exposes those tools; an MCP client inside the AI app calls them.
Source: modelcontextprotocol.io/docs/getting-started/intro · Reviewed Sep 2026
What risks does the MCP specification name?
The specification's security best practices page lists attacks and mitigations. The ones that matter most on employee devices:
- Local MCP server compromise. Local servers are binaries downloaded and run on the user's machine. The specification lists arbitrary code execution, no visibility into commands, command obfuscation, data exfiltration and data loss as risks, and says clients should warn that MCP servers run with the same privileges as the client.
- Token passthrough. Servers must not accept tokens that were not issued for them; passing them through breaks audit trails and trust boundaries.
- Confused deputy. Proxy servers to third-party APIs can let a malicious client obtain authorization without the user's consent.
- Server-side request forgery. A malicious server can steer a client to internal addresses or cloud metadata endpoints.
- Scope minimization. Broad scopes granted up front widen the damage of a stolen token.
Source: modelcontextprotocol.io/specification/latest/basic/security_best_practices · Reviewed Sep 2026
What controls should an AI security tool provide for MCP?
- An inventory of every MCP server configured on every device, including shadow MCP servers.
- An allow list of approved servers and the ability to block the rest.
- Per-tool-call evaluation before execution, not only a list of servers.
- Scoped permissions: what an agent may read, write and act on through each server.
- A record of each tool call tied to the person and the agent.
Which tools document MCP controls?
| Tool | What its public pages say about MCP |
|---|---|
| Bay | Inventories MCP servers; restricts MCP servers for Claude Code, Codex and Claude Desktop; Allow, Ask or Deny on pre-tool calls. |
| Noma Security | Discovers MCP servers and skills per endpoint agent; live registry of allowed servers. |
| Zenity | Discovers MCP servers per coding agent; MCP gateway; blocks or modifies tool calls before execution. |
| Onyx Security | Inline inspection of every tool call; MCP security solution. |
| Harmonic Security | Governs at the MCP layer; read, write and act permissions per MCP server. |
| Lasso Security | Open-source MCP gateway; discovers servers across Claude, Cursor and Windsurf; block, alert or sanitize. |
| Prompt Security | Maps agents and MCP servers; finds shadow MCP servers. |
| Koi (Palo Alto Networks) | Visibility into MCPs with risk scoring. |
| Bloom Security | Scales back overpermissioned MCP servers and configurations. |
Gateway or endpoint: where should MCP control sit?
A gateway sees MCP traffic that is routed through it, which suits remote servers and teams that can enforce routing. Local MCP servers run on the laptop and talk to the agent directly, so control at the endpoint, or inside the agent through its hooks, sees traffic a gateway may never receive. Many teams will use both.
Frequently asked questions
Are MCP servers safe to install?
They run with the privileges of the AI app that launches them. Treat them like any software from a third party: approve sources, review what they can reach, and restrict the rest.
What is shadow MCP?
MCP servers that employees configure without approval. Several tools in this guide discover them.
Related
Sources
- modelcontextprotocol.io/docs/getting-started/intro · Reviewed Sep 2026
- modelcontextprotocol.io/specification/latest/basic/security_best_practices · Reviewed Sep 2026
- Vendor pages as listed in each review · Reviewed Sep 2026