What is MCP security?
MCP security is the practice of securing the Model Context Protocol servers, tools, resources, identities, permissions, and evidence paths that extend what an AI agent can access or do.
Why can an MCP server increase AI agent risk?
An MCP server can expose data, tools, and actions to an agent. If ownership, authorization, scope, and tool behavior are unclear, the server can expand the agent's authority beyond the intended workflow.
What should be tested in an MCP server?
Teams should test authentication, authorization, token audience, exposed tools, tool parameters, data filtering, prompt injection through tool output, audit logs, and safe failure behavior.
Can MCP tool descriptions create prompt injection risk?
Yes. Tool descriptions, tool responses, and MCP-provided content can influence model context. They should be treated as untrusted data unless deterministic controls prevent them from overriding policy or authorization.
How should MCP data exposure be controlled?
MCP data exposure should be controlled with least-privilege scopes, per-user authorization, output filtering, data classification, logging minimization, and reviewable evidence for sensitive actions.
How does Orbyntis evaluate MCP security?
Orbyntis evaluates MCP security by mapping server ownership, tool authority, identity, authorization, prompt injection paths, data exposure, testing evidence, and operational impact across the agent workflow.