MCP makes it easy to give models powerful capabilities. That power needs care.
Risks
- Untrusted servers: a local server runs code on your machine; a malicious one can do anything you can.
- Tool poisoning: manipulative instructions hidden in tool descriptions or results.
- Prompt injection: content fetched by tools — web pages, emails, tickets — that tries to redirect the model.
- Excessive permissions: servers with broad credentials amplify mistakes.
- Changed behaviour: a server that updates its tools after you approved it.
- Data exfiltration: combining a tool that reads private data with one that sends data out.
For Users and Administrators
- Install servers only from trusted sources; review what they do.
- Pin versions and review updates.
- Grant minimal credentials and scopes.
- Keep approval on for tools with side effects.
- Be cautious combining servers that read sensitive data with ones that communicate externally.
For Server Developers
- Validate all inputs; never pass them to shells or queries unsafely.
- Enforce authorisation on every call.
- Return only necessary data.
- Keep descriptions accurate and free of instructions to the model.
For Host Developers
Show users what tools will do, require confirmation for sensitive actions, and isolate servers where possible.