Skip to content

MCP Security Best Practices

The main risks of connecting AI applications to MCP servers — malicious servers, injection, over-broad access — and how to reduce them.

Editorial team 2 min read

MCP makes it easy to give models powerful capabilities. That power needs care.

Risks

  • Untrusted servers: a local server runs code on your machine; a malicious one can do anything you can.
  • Tool poisoning: manipulative instructions hidden in tool descriptions or results.
  • Prompt injection: content fetched by tools — web pages, emails, tickets — that tries to redirect the model.
  • Excessive permissions: servers with broad credentials amplify mistakes.
  • Changed behaviour: a server that updates its tools after you approved it.
  • Data exfiltration: combining a tool that reads private data with one that sends data out.

For Users and Administrators

  • Install servers only from trusted sources; review what they do.
  • Pin versions and review updates.
  • Grant minimal credentials and scopes.
  • Keep approval on for tools with side effects.
  • Be cautious combining servers that read sensitive data with ones that communicate externally.

For Server Developers

  • Validate all inputs; never pass them to shells or queries unsafely.
  • Enforce authorisation on every call.
  • Return only necessary data.
  • Keep descriptions accurate and free of instructions to the model.

For Host Developers

Show users what tools will do, require confirmation for sensitive actions, and isolate servers where possible.

More in MCP

All MCP guides →
MCP Guide · 1 min

MCP Architecture: Hosts, Clients and Servers

How the Model Context Protocol is structured: the host application, the clients it creates and the servers that expose capabilities.

MCP 1 min read 2 Sep 2025

MCP Guide · 2 min

MCP Tools, Resources and Prompts

The three main things an MCP server can offer, who controls each, and when to use which.

MCP 2 min read 1 Sep 2025

MCP Guide · 1 min

MCP Transports: stdio and HTTP

How MCP messages travel: standard input and output for local servers, HTTP for remote ones, and how to choose.

MCP 1 min read 31 Aug 2025

MCP Guide · 1 min

Building Your First MCP Server

A walkthrough of the steps to create a simple MCP server that exposes a tool, and how to test it.

MCP 1 min read 30 Aug 2025