Home / Companies / AuthZed / Blog / Post Details
Content Deep Dive

MCP is Not Secure

Blog post from AuthZed

Post Details
Company
Date Published
Author
Sam Kim
Word Count
1,267
Company Posts That Month
4
Language
English
Hacker News Points
-
Post removed?
No
Summary

The Model Context Protocol (MCP) is designed to connect AI agents with tools, data sources, and APIs, focusing on standardization rather than security, which is left to the implementers. Although MCP includes detailed authentication mechanisms like OAuth 2.1 flows, token validation, and Protected Resource Metadata, it does not dictate the permissions or what authenticated users can do, leaving authorization decisions to those implementing the protocol. This gap has led to security breaches involving unauthorized data access, such as prompt injection attacks and over-privileged token use, underscoring the necessity for precise permission controls. While AI-based detection can aid in identifying anomalies, core authorization decisions must be deterministic to ensure security. As MCP evolves rapidly, with significant backing from major tech companies and a growing ecosystem, the need for adaptable and scalable authorization infrastructures becomes critical. This includes treating agents and tools as first-class subjects and ensuring permissions are reevaluated at every execution to prevent unauthorized data access.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
MCP 23 4,899 392 145 +47%
LLM 4 3,775 638 202 -32%
AI Agents 3 2,834 598 185 -18%
Platform Engineering 1 413 123 52 -15%
RAG 1 909 198 86 -19%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.