Skip to main content

Security Architecture

Threats

●       Prompt injection

●       Tool injection

●       Retrieval poisoning

●       Memory poisoning

●       Privilege escalation

●       Hidden instructions in documents

●       Fake knowledge sources

MCP-Specific Threats

●       Tool rug-pull — a connected MCP server changes its tool definitions after the host has already approved them.

●       Mix-up / issuer-confusion attacks — an authorization response is accepted from the wrong issuer; the 2026-07-28 spec mitigates this by requiring clients to validate the `iss` parameter (RFC 9207).

●       Untrusted tool input — treat every tool input as coming from the model, not directly from the user; enforce strict JSON Schema with `additionalProperties: false`.

●       Skill/Server supply-chain risk — a Skill or MCP server is executable content; vet sources the same way you would a new dependency.

Controls

●       Signed sources

●       Source trust scores

●       Sandboxed tool execution

●       Least privilege credentials

●       Tool allowlists

●       Input sanitization

●       Retrieval filtering

●       Human gates

●       OAuth issuer validation and scope-bound credentials for all remote MCP servers (New)