MCP security is the set of practices and controls that protect systems connected by the Model Context Protocol: the agents and clients that call tools, the MCP servers that expose them, and the data and systems those tools reach. It answers three questions: which servers are allowed to run, which caller may use which tool with which arguments, and what evidence exists of the calls made and the decisions on them.
The main risks
- Tool poisoning and changed definitions. A tool's description is an instruction to the model, so a malicious or silently changed definition can steer an agent. See tool poisoning.
- Injected instructions in tool output. Results fetched from a web page, ticket or document can carry instructions the model then follows.
- Over-broad access. One server credential shared by every agent, or destructive tools exposed to callers that only need to read.
- Supply chain. Servers installed from public registries run code with the permissions of whoever installed them.
- Authentication gaps. Authorization in the MCP specification is optional; for HTTP transports it builds on OAuth 2.1, while servers run over stdio take credentials from their environment. The details are in MCP OAuth 2.1 and PKCE explained.
- No connected record. Tool calls logged separately on each server cannot be followed from the agent's request to the outcome.
How it differs from an MCP gateway
An MCP gateway is one control within MCP security: the enforcement point in the call path that authenticates callers, authorizes tools and records decisions. MCP security also covers what happens before a server is installed (vetting its code and dependencies), how its credentials are stored and rotated, and what the server itself can reach on the network. MCP security is in turn one part of agentic AI security, which covers every path an agent acts through, not only MCP.
Where to go next
The full set of controls, from inventory to evidence, is in the MCP security guide, and the MCP server security checklist turns it into review items. Praesidia's controls for registered MCP servers are described on the MCP page.
Common questions
Is MCP secure by default?
The protocol defines how clients and servers talk and, for HTTP transports, how they authorize. It does not decide which tools an agent should use, or vet the code a server runs. Those decisions stay with whoever deploys it.
What is the first MCP security control to put in place?
An inventory. You cannot scope, monitor or revoke servers you do not know about, so start by listing which servers each agent connects to and which tools each server exposes.