How to secure MCP: threats and defenses
Blog post from Stytch
Model Context Protocol (MCP), likened to a "USB-C for AI agents," enables large language models to connect with various tools and data sources, but it presents significant security challenges. Early adopters have highlighted vulnerabilities such as tool-poisoning attacks, dynamic tool redefinition, and cross-server tool shadowing, which exploit the protocol's reliance on implicit trust and lack of authentication. These security gaps allow malicious servers to execute unauthorized actions, such as exfiltrating sensitive data or altering AI behavior. In response, the community is advancing MCP's security by proposing improvements like integrating external identity providers, enforcing scope-based access control, and adopting defense-in-depth strategies. These measures aim to shift from a trust-based model to a more secure, permission-based framework, enhancing the safety of MCP's powerful capabilities while maintaining productivity benefits.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 83 | 2,460 | 213 | 96 | -18% |
| AI Agents | 11 | 1,754 | 421 | 135 | -14% |
| LLM | 5 | 3,482 | 526 | 172 | -8% |
| AI Guardrails | 1 | 162 | 70 | 33 | +5% |
| Secrets Management | 1 | 1,161 | 159 | 70 | +7% |
| Vector Search | 1 | 1,525 | 253 | 110 | -6% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.