Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

MCP servers and Skills: what agentic AI teams need to govern


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12518
Topic starter  

TL;DR: Among 200-plus popular MCP servers and agent Skills in production, 76% of MCP servers carry high-risk capabilities, one in four expose arbitrary code execution, and 62% of Skills have risky characteristics with no audit trail, according to Noma Security. The findings show agentic AI risk is split across visible and invisible layers that current tooling does not govern well.

NHIMG editorial — based on content published by Noma Security: Lethal by Design, which examines how AI agents are exposed through MCP servers and Skills

By the numbers:

Questions worth separating out

Q: How should teams govern AI agents that use MCP?

A: Treat each connected agent as a non-human identity with an owner, a scope, and a review cycle.

Q: Why do AI agents create a different access-risk profile than traditional applications?

A: AI agents can chain actions, call multiple tools, and change behaviour based on context, so one credential can enable more than one operational path.

Q: What breaks when an agent capability has no audit trail?

A: Accountability breaks first, followed by detection and forensics.

Practitioner guidance

  • Separate MCP and Skill governance Inventory MCP servers and Skills independently, then assign different approval, logging, and containment rules to each layer because they do not expose the same level of runtime visibility.
  • Block arbitrary code execution paths Treat any agent integration that can execute code as a privileged pathway and require containment, explicit approval, and tighter runtime monitoring before production use.
  • Require attributable action logs Do not allow production agent capabilities that cannot produce a traceable record of tool use, data access, and action timing because unlogged behaviour cannot be certified or investigated.

What's in the full report

Noma Security's full research covers the operational detail this post intentionally leaves for the source:

  • The production sample methodology used to assess 200-plus MCP servers and agent Skills
  • The capability breakdown behind the 76% high-risk MCP server figure and the one-in-four code execution finding
  • The No Excessive CAP framework applied to continuous governance of Capabilities, Autonomy, and Permissions
  • The full attack-chain examples showing how credentials, CRM records, and production systems were weaponised

👉 Read Noma Security's Lethal by Design research on MCP and Skill risk →

MCP servers and Skills: what agentic AI teams need to govern?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12102
 

Agentic AI risk is now a capability governance problem, not a model risk problem. The article shows that the highest-risk surface sits in the agent's connected capabilities, not in the language model itself. That shifts the control question from prompt quality to what tools, actions, and permissions can be exercised at runtime. Practitioners should treat capability scope as the first-line identity control for agentic systems.

A few things that frame the scale:

  • 98% of companies plan to deploy even more AI agents within the next 12 months, despite documented rogue behaviour in 80% of current deployments, according to AI Agents: The New Attack Surface report.
  • Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.

A question worth separating out:

Q: What is the difference between agent permissions and agent autonomy?

A: Permissions define what an agent is allowed to reach, while autonomy defines how independently it can choose actions and sequence them. A system can have broad permissions but little autonomy, or limited permissions with high runtime decision freedom. Governance must address both, because reducing one does not control the other.

👉 Read our full editorial: AI agent attack surface grows through MCP and Skill risk



   
ReplyQuote
Share: