Secure MCP integrations by treating server-provided text and tool results as untrusted input, preserving their origin, limiting tool and credential privileges, and enforcing security policy in deterministic authorization, transport, and runtime controls. Prompts and tool annotations can guide a model or user interface, but they cannot make an LLM immune to prompt injection.
What is the threat boundary in an MCP session?
The risk is not limited to one MCP server. A host may combine tools from several servers with private-data access, untrusted-content exposure, and external communication. Content returned by one tool can influence what the model asks another tool to do, so review the combined capabilities available in a session—not only each server in isolation.
Treat tool descriptions and annotations, server instructions, tool results, resources, and server-served skills as untrusted model input unless a separate verification and policy mechanism establishes otherwise. A connected server is not automatically authoritative. Preserve the identity of the server that supplied each item; do not flatten remote content so it appears to have the authority of system policy, user instructions, or trusted local material.
The stable MCP Skills extension requires hosts to treat served skill content as untrusted and keep its originating server identity visible. Its security rules also prohibit presenting a remote skill as indistinguishable from a local skill.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Why prompts and tool annotations cannot prevent prompt injection
Server instructions are guidance, not enforcement
Server instructions may help a model use a server, but hosts decide how to handle them; some hosts may not inject them into the system prompt. Even when included, instructions cannot guarantee model behavior. MCP maintainer Ola Hungerford advises: “Don’t rely on instructions for any critical actions that need to happen in conjunction with other actions, especially in security or privacy domains. These are better implemented as deterministic rules or hooks.” Put security- and privacy-critical requirements in controls that can be enforced, not in instructions the model may follow.
The MCP project’s guidance on server instructions discusses their role and limits. Treat instructions as useful operational context, not permission grants or a security boundary.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Annotations are untrusted hints
Annotations such as read-only or destructive-operation hints can help a client decide what to display or whether to ask for approval. They are static metadata, can be misstated by an untrusted server, and do not stop prompt injection. Enforce actual permissions through authorization, transport, and runtime logic. The MCP project’s tool-annotations guidance explicitly warns that annotations do not make a model resistant to injection.
Limit the consequences of tool poisoning and cross-tool chains
Assess what a model can do when capabilities are combined. In particular, consider whether untrusted content can influence a tool that reads private data or sends information outside the environment. The MCP project’s risk discussion uses an illustrative research demonstration; it is not a prevalence statistic or evidence that a particular attack rate applies to your deployment.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
- Give tools only the credentials, scopes, data, and actions they need. Avoid broad credentials shared across unrelated tools.
- Isolate tool execution and restrict network egress where the deployment allows it.
- Require explicit authorization for sensitive actions and operations with external consequences.
- Keep policy checks in the host, runtime, transport, or authorization layer so a model cannot bypass them merely by following injected content.
- Review tool combinations as well as individual tools: map which tools can read private data, consume untrusted content, or communicate externally.
These are implementation controls, not a claim that MCP mandates one particular sandbox product or architecture. The appropriate boundary depends on the host, runtime, credentials, and tools in your deployment.
Apply stricter controls to MCP-served skills
The stable Skills extension treats server-served skill text as untrusted model input and describes it as a higher-risk surface than a remote tool invocation. Its security requirements give hosts concrete safeguards:
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Keep a host-assigned server identity attached to served skill content and visible to the model or user.
- Require explicit per-skill user approval before skill content can cause host-side code execution; do not permit implicit execution.
- Bind resource reads to the skill’s origin. Do not allow a remote skill to silently read resources from another server.
- Require user approval for cross-origin resource access, identifying the servers involved.
- Prevent remote skill names from shadowing local skills or skills from another origin.
- Do not let a remote skill silently widen its permissions.
The extension states: “Hosts MUST treat MCP-served skill content as untrusted model input, subject to the same prompt-injection defenses applied to any server-provided text.” It also states: “Hosts MUST NOT allow MCP-served skill content to cause host-side code execution without explicit per-skill user approval.” See the stable Skills extension specification for the normative requirements.
Choose the right authorization boundary for remote tools
For a protected remote MCP service, authenticate and authorize at the HTTP boundary. Verify credentials before a protected request reaches a tool handler, and pass verified identity context into the handler. If required credentials are absent or invalid, return HTTP 401 with a WWW-Authenticate header pointing to Protected Resource Metadata. Do not disguise an unauthenticated request as an ordinary tool-level error.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteBest Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
| Pattern | How it works | When it fits |
|---|---|---|
| Per-server authorization | Require a valid bearer token on every request. | Use when every tool on the server is sensitive. |
| Per-tool authorization | Inspect the incoming JSON-RPC request, identify protected tool calls, and enforce authentication for those calls while allowing intentionally public tools. | Use when public and protected tools deliberately coexist. |
For protected calls, validate the bearer token and user identity before invoking the handler. The MCP Apps authorization guide demonstrates JWT validation using an identity provider’s JWKS endpoint and issuer. Treat that as an implementation pattern: adapt validation to your identity provider, token format, framework, and MCP SDK rather than copying it without review.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Check the protocol and SDK versions before changing deployment controls
The MCP project announced specification version 2026-07-28 on July 28, 2026. The release introduces a stateless core, adds Mcp-Method and Mcp-Name headers for routing and metering, and changes authorization, including client validation of the OAuth issuer and binding credentials to their issuing authorization server. The announcement says Dynamic Client Registration (DCR) is deprecated in favor of Client ID Metadata Documents (CIMD), while remaining compatible for the time being.
Before relying on release-specific behavior, verify the protocol version implemented by each server, client, gateway, and SDK in your deployment, then consult the applicable migration notes. The official announcement of the 2026-07-28 specification is the source for these release changes; do not assume all deployed components have adopted them.
Quick Recap
Implementation review checklist
- Inventory the session. List every connected server, tool, resource, and skill, along with the data and external actions each can reach.
- Mark provenance. Preserve server origin for metadata, instructions, results, resources, and skills wherever they enter model context.
- Separate hints from policy. Use instructions and annotations for guidance or user experience only; enforce sensitive decisions in deterministic controls.
- Reduce capability. Narrow credentials and scopes, isolate execution, restrict egress, and require authorization for sensitive or externally consequential operations.
- Protect remote requests. Choose per-server or per-tool authorization deliberately; validate credentials at the HTTP boundary and propagate verified identity to handlers.
- Gate skill execution and access. Require per-skill approval for execution actions, bind resources to origin, and prevent name collisions or silent permission expansion.
- Validate compatibility. Check protocol and SDK versions across the deployment before adopting version-specific transport or authorization behavior.
- Test combinations. Exercise realistic chains in which untrusted tool content could affect a private-data or external-communication tool, and confirm that runtime controls block unauthorized outcomes.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.

