MCP Security Checklist: How to Vet and Run MCP Servers Safely in 2026
MCP is not safe by default. Twelve checks, by phase, for vetting an MCP server before install and constraining it at the call, in flight and on update.
16 articles with this tag.
MCP is not safe by default. Twelve checks, by phase, for vetting an MCP server before install and constraining it at the call, in flight and on update.
Arcade.dev raised $60M in June 2026 for an agent authorization layer. What scoped permissions, MCP tool policy and audit trails mean for your agent stack.
Agentjacking hijacks AI coding agents with a fake Sentry error. Tenet found 2,388 exposed orgs, 100+ agents running attacker code, an 85% success rate.
An IETF Internet-Draft names 6 recurring MCP vulnerability classes and states that the MCP specification defines no normative security requirements.
An AI agent provisioned five AWS instances to port-scan DN42 and ran up $6,531.30 in about 24 hours. Cost, scope and rate are tool permissions, not prompt text.
Varonis and Imperva tested OpenClaw agents in June 2026: 2 of 4 phishing scenarios leaked live secrets. Identity-bound tool permissions are the fix.
An Agent Bill of Materials lists every skill, plugin, MCP server, credential and paired device an agent can reach. OpenClaw's ClawJacked bug is why you need one.
Cisco Cloud Control puts AI agents, MCP connectors and a 50-partner tool marketplace inside infrastructure operations. What admission control that now requires.
VIPER-MCP scanned 39,884 MCP server repos and confirmed 106 zero-days, 67 with CVE IDs. Agent tools need code-level taint analysis, not trust prompts.
Microsoft's Agent Control Specification evaluates agent policy at 8 intervention points and returns 1 of 5 verdicts: allow, warn, deny, escalate, transform.
The NSA's May 2026 MCP guidance treats agent tooling as infrastructure: inventory every server, verify tool changes, and scan before trust drifts.
Ruleset v2026.06.05 adds five rules for a publisher family targeting ~/.claude and fixes eight noisy patterns. Stage 2 now reads ~6 findings per skill, not ~15.
OX Security found a remote code execution design flaw in MCP's official SDKs: 10 CVEs, 30+ disclosures, 7,000+ exposed servers. Treat MCP servers as code.
18 security auditing skills installed and scored out of 50. The top five ship 146 vulnerability vectors, 11 language footgun guides and live dependency checks.
MCP tool poisoning hides attacker instructions in tool description metadata your model reads and your UI never shows. How it works, and how to detect it.
SkillJect poisons agent skills and averages 80.7% attack success on Claude Code. Four skill scanners caught it 61.5% of the time. The 4 rules we shipped.