Guide
Inside MCP Security: A Research Guide on Emerging Risks
This research guide explores the emerging security risks of the Model Context Protocol (MCP), which connects LLMs to external tools and data sources. While MCP unlocks powerful capabilities, it introduces risks such as supply chain vulnerabilities, untrusted tool execution, prompt injection, and credential exposure. The guide highlights differences between local and remote MCP servers, both of which can enable malicious code execution or data exfiltration if not properly secured. It also outlines practical defenses like least-privilege access, auditing tools before use, sandboxing, and using trusted registries. The key takeaway is that MCP must be treated like any high-privilege integration surface, requiring strict governance, validation, and monitoring to safely adopt.
