MCP Security Engineering

MCP Security Engineering

Replacement notice

The earlier security guide generalized legacy transport behavior, an implementation-specific CVE, and hypothetical methods into protocol facts. This replacement is scoped to the current specification. The original remains in the dumpster fact-check archive.

Key jargon

Term Meaning
Tool poisoning Untrusted tool metadata or behavior misleading a host, model, or user. Tool annotations must be treated as untrusted unless their server is trusted. S1
Confused deputy A privileged component is induced to use its authority for an unauthorized party or purpose. S2
Audience binding Restricting an access token to its intended resource server. S2
Prompt injection Untrusted content attempts to influence model behavior; impact depends on the surrounding permissions and controls. S1

Current trust model

MCP standardizes protocol messages, not end-to-end trust. Hosts remain responsible for consent, tool review, authorization, data protection, validation, and safe presentation of results. The specification says tool descriptions and annotations are untrusted unless obtained from a trusted server. S1

flowchart LR
    A["Untrusted request or content"] --> B["Host validates identity scope and schema"]
    B --> C["User confirms consequential tool effect"]
    C --> D["Server executes least privilege and returns evidence"]

Diagram semantics checked against the current MCP security principles on 2026-09-02.

Protocol changes that invalidate the old guide

CVE scope correction

CVE-2025-6515 affects oatpp-mcp, whose legacy SSE endpoint used an instance pointer as a predictable session identifier. It is not evidence that MCP generally creates predictable sessions, and its session-hijacking scenario does not describe the stateless 2026-07-28 core. S4

Required engineering controls