MCP Security Checklist: How to Vet and Run MCP Servers Safely in 2026
MCP is not safe by default. Twelve checks, by phase, for vetting an MCP server before install and constraining it at the call, in flight and on update.
6 articles with this tag.
MCP is not safe by default. Twelve checks, by phase, for vetting an MCP server before install and constraining it at the call, in flight and on update.
Agentjacking hijacks AI coding agents with a fake Sentry error. Tenet found 2,388 exposed orgs, 100+ agents running attacker code, an 85% success rate.
Varonis and Imperva tested OpenClaw agents in June 2026: 2 of 4 phishing scenarios leaked live secrets. Identity-bound tool permissions are the fix.
Snyk scanned 3,984 AI agent skills: 36.82% had a security flaw, 13.4% a critical one, 76 carried confirmed malware and 8 were still live at publication.
MCP tool poisoning hides attacker instructions in tool description metadata your model reads and your UI never shows. How it works, and how to detect it.
SkillJect poisons agent skills and averages 80.7% attack success on Claude Code. Four skill scanners caught it 61.5% of the time. The 4 rules we shipped.