MCP Security Checklist: How to Vet and Run MCP Servers Safely in 2026
MCP is not safe by default. Twelve checks, by phase, for vetting an MCP server before install and constraining it at the call, in flight and on update.
Research on how malicious instructions, credential exfiltration and typosquats reach AI agents through skills, plugins and packages — and what actually stops them.
An AI agent that installs a skill is executing someone else's instructions with your credentials, in your repository, on your machine. That makes the skill registry a supply chain in the same sense npm and PyPI are — and it inherits the same attack classes: typosquatting, dependency confusion, maintainer compromise, and payloads that stay dormant until a specific trigger.
It also adds a new one. Because the payload is natural-language instructions rather than executable code, it can target the agent's judgment instead of the runtime: text that reads as helpful documentation to a human reviewer but tells the model to exfiltrate an environment variable or silently widen a permission. The posts below document real incidents, break down the techniques, and cover the defenses — scanning before install, dual-side verification, and pinning what you depend on.
24 articles in this guide
MCP is not safe by default. Twelve checks, by phase, for vetting an MCP server before install and constraining it at the call, in flight and on update.
Arcade.dev raised $60M in June 2026 for an agent authorization layer. What scoped permissions, MCP tool policy and audit trails mean for your agent stack.
Agentjacking hijacks AI coding agents with a fake Sentry error. Tenet found 2,388 exposed orgs, 100+ agents running attacker code, an 85% success rate.
An IETF Internet-Draft names 6 recurring MCP vulnerability classes and states that the MCP specification defines no normative security requirements.
An AI agent provisioned five AWS instances to port-scan DN42 and ran up $6,531.30 in about 24 hours. Cost, scope and rate are tool permissions, not prompt text.
Varonis and Imperva tested OpenClaw agents in June 2026: 2 of 4 phishing scenarios leaked live secrets. Identity-bound tool permissions are the fix.
An Agent Bill of Materials lists every skill, plugin, MCP server, credential and paired device an agent can reach. OpenClaw's ClawJacked bug is why you need one.
Cisco Cloud Control puts AI agents, MCP connectors and a 50-partner tool marketplace inside infrastructure operations. What admission control that now requires.
Vercel's skills.sh API exposes 600,000+ agent skills to any tool holding an OIDC token. Pin the content hash, not the name, before you let an agent install one.
VIPER-MCP scanned 39,884 MCP server repos and confirmed 106 zero-days, 67 with CVE IDs. Agent tools need code-level taint analysis, not trust prompts.
Microsoft's Agent Control Specification evaluates agent policy at 8 intervention points and returns 1 of 5 verdicts: allow, warn, deny, escalate, transform.
The NSA's May 2026 MCP guidance treats agent tooling as infrastructure: inventory every server, verify tool changes, and scan before trust drifts.
OX Security found a remote code execution design flaw in MCP's official SDKs: 10 CVEs, 30+ disclosures, 7,000+ exposed servers. Treat MCP servers as code.
A Hugging Face repo typosquatted OpenAI's Privacy Filter, hit #1 trending on 244K downloads in 18 hours, then ran a Rust infostealer. The full attack chain.
Snyk scanned 3,984 AI agent skills: 36.82% had a security flaw, 13.4% a critical one, 76 carried confirmed malware and 8 were still live at publication.
MCP tool poisoning hides attacker instructions in tool description metadata your model reads and your UI never shows. How it works, and how to detect it.
Langflow's CVSS 9.3 unauthenticated RCE was exploited in the wild 20 hours after disclosure, with no public PoC. Three LangChain and LangGraph CVEs followed.
TeamPCP hid a credential stealer in a WAV file inside telnyx 4.87.1 on PyPI, using tokens stolen from litellm three days earlier. Why the cascade evades review.
Claude Code skills run with your files, shell and credentials. ClawHavoc put 1,184 malicious skills in one registry. How to check one before you install.
TeamPCP pushed a credential stealer into litellm 1.82.7 and 1.82.8 on PyPI via a compromised Trivy action. What it did, and why AI skills are next.
ClawHavoc was a January 2026 poisoning campaign on ClawHub: 1,184 malicious agent skills from 12 author IDs, most delivering the AMOS macOS stealer.
Three registry security models - reactive moderation, install-time scanning, and dual-side verification with a tree hash - and the attack each one misses.
Koi Security found 341 malicious skills in 2,857 listings. SkillSafe scans before sharing, re-scans on install, and blocks archives that changed in between.
Dual-side verification scans a shared AI skill twice, once by the publisher and once by you, then compares both reports and a SHA-256 tree hash before install.