# Security Architecture

## Threats

● Prompt injection

● Tool injection

● Retrieval poisoning

● Memory poisoning

● Privilege escalation

● Hidden instructions in documents

● Fake knowledge sources

## MCP-Specific Threats

● Tool rug-pull — a connected MCP server changes its tool definitions after the host has already approved them.

● Mix-up / issuer-confusion attacks — an authorization response is accepted from the wrong issuer; the 2026-07-28 spec mitigates this by requiring clients to validate the `iss` parameter (RFC 9207).

● Untrusted tool input — treat every tool input as coming from the model, not directly from the user; enforce strict JSON Schema with `additionalProperties: false`.

● Skill/Server supply-chain risk — a Skill or MCP server is executable content; vet sources the same way you would a new dependency.

## Controls

● Signed sources

● Source trust scores

● Sandboxed tool execution

● Least privilege credentials

● Tool allowlists

● Input sanitization

● Retrieval filtering

● Human gates

● OAuth issuer validation and scope-bound credentials for all remote MCP servers (New)