MCP Security Engineering
MCP Security Engineering
The earlier security guide generalized legacy transport behavior, an implementation-specific CVE, and hypothetical methods into protocol facts. This replacement is scoped to the current specification. The original remains in the dumpster fact-check archive.
Key jargon
| Term | Meaning |
|---|---|
| Tool poisoning | Untrusted tool metadata or behavior misleading a host, model, or user. Tool annotations must be treated as untrusted unless their server is trusted. S1 |
| Confused deputy | A privileged component is induced to use its authority for an unauthorized party or purpose. S2 |
| Audience binding | Restricting an access token to its intended resource server. S2 |
| Prompt injection | Untrusted content attempts to influence model behavior; impact depends on the surrounding permissions and controls. S1 |
Current trust model
MCP standardizes protocol messages, not end-to-end trust. Hosts remain responsible for consent, tool review, authorization, data protection, validation, and safe presentation of results. The specification says tool descriptions and annotations are untrusted unless obtained from a trusted server. S1
flowchart LR
A["Untrusted request or content"] --> B["Host validates identity scope and schema"]
B --> C["User confirms consequential tool effect"]
C --> D["Server executes least privilege and returns evidence"]Diagram semantics checked against the current MCP security principles on 2026-09-02.
Protocol changes that invalidate the old guide
- The
2026-07-28core is stateless and removed protocol-level sessions andMcp-Session-Id. S3 - HTTP+SSE is deprecated; current implementations use Streamable HTTP or stdio as specified. S3
- Capability/version information is carried per request, with optional up-front
server/discover. S3 - Roots, Sampling, and Logging are deprecated for new implementations; Tasks is an extension. S3
CVE scope correction
CVE-2025-6515 affects oatpp-mcp, whose legacy SSE endpoint used an instance pointer as a predictable session identifier. It is not evidence that MCP generally creates predictable sessions, and its session-hijacking scenario does not describe the stateless 2026-07-28 core. S4
Required engineering controls
- Inventory and trust MCP servers before exposing their capabilities.
- Validate tool inputs and results; constrain paths, destinations, resource identifiers, sizes, and rates.
- Bind user identity, authorization, and token audience to every consequential request.
- Never pass a client token through to an upstream service; obtain a separately scoped upstream credential. S2
- Present an accurate effect preview and obtain explicit consent for sensitive operations. S1
- Isolate local server processes and avoid ambient credentials.
- Record protocol version, server identity, tool schema, authorization decision, request, and observed effect.