TL;DR: MCP creates a high-risk model-agent layer because natural-language requests can drive privileged actions, making prompt injection, replay, lateral movement, and data exfiltration practical attack paths according to WorkOS. The governance problem is not just transport security but assuming that unsafe intent can be reliably filtered after a model has already shaped execution.
Editorial analysis by NHI Mgmt Group, based on content published by WorkOS: “Best practices for securing MCP model-agent interactions”.
Key questions
Q: What breaks when MCP requests are not validated at each handoff and memory access point?
A: When MCP requests are not validated at each handoff and memory access point, attackers can move from one permitted action to a broader compromise.
Q: Why do over-privileged agents increase risk in model-agent systems?
A: Because the model does not need direct access to systems if it can steer an agent that already has it.
Q: What are the signs that MCP traffic is being replayed or reused?
A: Repeated privileged actions, stale requests appearing in new sessions, and commands that succeed without a fresh user context are all warning signs.
Practitioner guidance
- Implement validation gateways for MCP traffic Force every model-generated request through a policy layer that checks schema, context, and allowed action before an agent can execute it.
- Scope agent credentials to the minimum action set Assign short-lived credentials per request or session, and separate read, write, and destructive actions into distinct agent scopes.
- Require freshness controls on all privileged messages Use nonces, timestamps, and proof-of-possession so a captured MCP message cannot be replayed across sessions or clients.
Bottom line: MCP turns natural language into a privileged execution path, so prompt injection and command confusion become control-plane problems rather than simple content-filtering issues.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Model-agent interaction is a governed execution layer, not a messaging detail. MCP changes the security question from "is the message authenticated" to "who is allowed to turn this message into action." That distinction matters because the model can reshape intent before the agent ever evaluates it. For identity programmes, the control point moves upstream to request validation, scoped execution, and context-aware authorisation.
A few things that frame the scale:
- 24,008 unique secrets were exposed in MCP configuration files in 2025 alone, the protocol's first year of widespread adoption, according to the State of Secrets Sprawl 2026.
A question worth separating out:
Q: How should security teams balance human approval with autonomous agent actions?
A: High-risk actions should require explicit step-up approval, while low-risk reads can remain automated under tight scope. The goal is not to block all automation, but to reserve human judgment for destructive operations, bulk exports, and privilege changes. If approval never appears in the path, then the trust model is too broad for the action being taken.
👉 Read our full editorial: Securing MCP model-agent interactions starts with privilege control