Join our Newsletter — 33% off our NHI Course

MCP security risks for AI agents: are your controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: MCP standardises how LLMs discover tools and trigger actions, but Lasso Security notes that concentrated capability access, weak scoping, and limited visibility can turn one misconfiguration into broad misuse or exfiltration. That makes protocol-level governance, auditability, and least-privilege boundaries decisive for enterprise AI programmes.

Editorial analysis by NHI Mgmt Group, based on content published by Lasso Security: “MCP: Enabling Controlled & Composable AI Systems”.

Key questions

Q: What breaks when MCP integrations are not governed tightly?

A: Tool trust breaks first, then command integrity, then secret exposure.

Q: Why does MCP increase the impact of a compromised server?

A: MCP increases the impact of a compromised server because the server can sit inside a shared orchestration path and return data or actions that look legitimate to the agent.

Q: What are the signs that MCP governance is failing?

A: Common signs include agents reaching systems outside their intended workflow, incomplete audit trails for tool use, and data retrieval that cannot be tied back to a clear business purpose.

Practitioner guidance

  • Define capability-level access boundaries Map each MCP tool to the minimum authority required, then separate read-only, write, and multi-step actions so one capability cannot silently expand into another.
  • Instrument orchestrator and server telemetry Log agent identity, tool name, parameters, response class, and approval context for every MCP call so investigations can reconstruct who did what and when.
  • Approve third-party MCP servers like software supply chain artifacts Review provenance, authentication behaviour, and exposed capabilities before introducing any community or vendor server into production workflows.

Bottom line: MCP can improve AI integration consistency while also concentrating access risk in one protocol layer if scopes and server trust are weak.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21364
 

MCP is not just an integration pattern, it is an identity boundary. The moment a model can discover tools and trigger actions through a standard interface, the question changes from application connectivity to delegated authority. That makes tool scoping, auditability, and policy enforcement part of the identity stack, not optional platform extras. Practitioners should treat MCP servers like privileged non-human identities with explicit lifecycle and access governance.

A few things that frame the scale:

  • Only 18% of MCP server deployments implement any form of access scoping for tool permissions, according to The State of MCP Server Security 2025.
  • 53% of MCP servers expose credentials through hard-coded values in configuration files, which shows how quickly protocol adoption becomes a secrets governance problem.

A question worth separating out:

Q: Who is accountable when an MCP-connected agent misuses a tool?

A: Accountability sits with the organisation that defined the tool exposure, the policy layer, and the oversight model, because MCP does not remove the need for governance. If a server, orchestrator, or registry is trusted without review, that trust decision becomes the control failure, not just the model’s behaviour.

👉 Read our full editorial: MCP concentrates risk in AI tool orchestration and access control



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21364
 

MCP is not just an integration pattern, it is an identity boundary. The moment a model can discover tools and trigger actions through a standard interface, the question changes from application connectivity to delegated authority. That makes tool scoping, auditability, and policy enforcement part of the identity stack, not optional platform extras. Practitioners should treat MCP servers like privileged non-human identities with explicit lifecycle and access governance.

A few things that frame the scale:

  • Only 18% of MCP server deployments implement any form of access scoping for tool permissions, according to The State of MCP Server Security 2025.
  • 53% of MCP servers expose credentials through hard-coded values in configuration files, which shows how quickly protocol adoption becomes a secrets governance problem.

A question worth separating out:

Q: Who is accountable when an MCP-connected agent misuses a tool?

A: Accountability sits with the organisation that defined the tool exposure, the policy layer, and the oversight model, because MCP does not remove the need for governance. If a server, orchestrator, or registry is trusted without review, that trust decision becomes the control failure, not just the model’s behaviour.

👉 Read our full editorial: MCP concentrates risk in AI tool orchestration and access control



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21364
 

MCP is becoming the identity boundary for enterprise AI tool use: The main governance shift is that capability discovery, authorisation, and audit now happen at the protocol layer, not inside each downstream app. That collapses the old assumption that integrations are merely transport. Practitioners should treat MCP as a control plane for non-human access, with all the lifecycle and oversight that implies.

A few things that frame the scale:

  • 24,008 unique secrets were exposed in MCP configuration files in 2025 alone, the protocol's first year of widespread adoption, according to the State of Secrets Sprawl 2026.

A question worth separating out:

Q: How should teams govern MCP at scale without overexposing tools?

A: Teams should govern MCP as a capability-based control plane, with explicit approval for server provenance, granular scoping for each tool, and monitoring that covers every request and response. The goal is to keep discoverability useful while preventing shared interfaces from becoming shared privilege.

👉 Read our full editorial: MCP concentrates risk in AI tool orchestration and access control


This post was modified 3 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.