Best AI Security markBest AI Security

Guide · Checked against vendor sites, September 2026

MCP security: how to control what MCP servers let AI agents do

The verdict

MCP security means knowing which MCP servers your agents connect to, limiting what each one can do, and checking tool calls before they run. The MCP specification itself warns that local MCP servers run with the same privileges as the client, so an unvetted server on a laptop can execute commands and read data with the user's access.

Part of the University: Basics track

What is MCP?

The Model Context Protocol is an open-source standard for connecting AI applications to external systems. Its documentation describes it as "like a USB-C port for AI applications": one way for an AI app such as Claude, ChatGPT, Visual Studio Code or Cursor to connect to data sources, tools and workflows. An MCP server exposes those tools; an MCP client inside the AI app calls them.

Source: modelcontextprotocol.io/docs/getting-started/intro · Reviewed Sep 2026

What risks does the MCP specification name?

The specification's security best practices page lists attacks and mitigations. The ones that matter most on employee devices:

  • Local MCP server compromise. Local servers are binaries downloaded and run on the user's machine. The specification lists arbitrary code execution, no visibility into commands, command obfuscation, data exfiltration and data loss as risks, and says clients should warn that MCP servers run with the same privileges as the client.
  • Token passthrough. Servers must not accept tokens that were not issued for them; passing them through breaks audit trails and trust boundaries.
  • Confused deputy. Proxy servers to third-party APIs can let a malicious client obtain authorization without the user's consent.
  • Server-side request forgery. A malicious server can steer a client to internal addresses or cloud metadata endpoints.
  • Scope minimization. Broad scopes granted up front widen the damage of a stolen token.

Source: modelcontextprotocol.io/specification/latest/basic/security_best_practices · Reviewed Sep 2026

What controls should an AI security tool provide for MCP?

  • An inventory of every MCP server configured on every device, including shadow MCP servers.
  • An allow list of approved servers and the ability to block the rest.
  • Per-tool-call evaluation before execution, not only a list of servers.
  • Scoped permissions: what an agent may read, write and act on through each server.
  • A record of each tool call tied to the person and the agent.

Which tools document MCP controls?

From public vendor pages reviewed September 2026.
ToolWhat its public pages say about MCP
BayInventories MCP servers; restricts MCP servers for Claude Code, Codex and Claude Desktop; Allow, Ask or Deny on pre-tool calls.
Noma SecurityDiscovers MCP servers and skills per endpoint agent; live registry of allowed servers.
ZenityDiscovers MCP servers per coding agent; MCP gateway; blocks or modifies tool calls before execution.
Onyx SecurityInline inspection of every tool call; MCP security solution.
Harmonic SecurityGoverns at the MCP layer; read, write and act permissions per MCP server.
Lasso SecurityOpen-source MCP gateway; discovers servers across Claude, Cursor and Windsurf; block, alert or sanitize.
Prompt SecurityMaps agents and MCP servers; finds shadow MCP servers.
Koi (Palo Alto Networks)Visibility into MCPs with risk scoring.
Bloom SecurityScales back overpermissioned MCP servers and configurations.

Gateway or endpoint: where should MCP control sit?

A gateway sees MCP traffic that is routed through it, which suits remote servers and teams that can enforce routing. Local MCP servers run on the laptop and talk to the agent directly, so control at the endpoint, or inside the agent through its hooks, sees traffic a gateway may never receive. Many teams will use both.

Frequently asked questions

Are MCP servers safe to install?

They run with the privileges of the AI app that launches them. Treat them like any software from a third party: approve sources, review what they can reach, and restrict the rest.

What is shadow MCP?

MCP servers that employees configure without approval. Several tools in this guide discover them.

Related

Sources