Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Secure MCP as a chain of trust boundaries—not as a server-hardening task alone. A model can choose tools and arguments based on natural-language instructions and untrusted content returned by other tools; an MCP server may then act with delegated privileges. Limit what each connection can do, treat tool definitions and outputs as untrusted, validate data throughout the workflow, and require informed human approval for consequential actions.

Where MCP security boundaries begin and end

An MCP workflow can involve a host application, an MCP client, one or more MCP servers, the tools those servers expose, external services, and the model’s context. Each server connection and each tool is a distinct trust boundary. A weakness in any one of them can affect the rest of the workflow: a tool’s output may influence the model’s next decision, which may trigger a different tool or send data to an external service.

This makes security a workflow property. A trusted server can still expose an overpowered tool; a well-protected tool can still receive manipulated arguments; and a legitimate response can still contain text that should not be treated as an instruction. OWASP’s MCP Security – OWASP Cheat Sheet Series and OWASP MCP Top 10 describe risks across these connected components rather than treating the protocol as the only security boundary.

How prompt injection can travel through tools

Prompt injection can enter an agent through retrieved or processed content, not just through a user’s message. For example, a tool may return a web page, document, or OCR-extracted text containing instructions aimed at the model. If the model treats that text as trusted direction, it may call another tool, pass along sensitive context, or take an action the user did not intend.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

The influence can also start with the tool interface itself. OWASP describes tool poisoning as malicious instructions embedded in a tool’s description, parameter schema, or returned values. A related “rug pull” is a change to a server’s tool definitions after they have been reviewed or approved. Tool shadowing or cross-server escalation occurs when one server’s tool influences agent behavior involving tools from another server. Review therefore needs to cover tool names, descriptions, schemas, and changes over time—not only the server package.

OWASP’s MCP Top 10 also identifies contextual prompt injection through untrusted text, including text extracted through OCR or other processing. It calls out context injection and over-sharing when working memory or intermediate outputs cross tasks, users, agents, or sessions. Keep those contexts separated and do not assume that content is safe because it arrived through an approved tool.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Key MCP security risks and the controls that address them

Risk How it can affect a workflow Useful control
Tool or context manipulation Poisoned descriptions, schemas, changed definitions, or returned content can steer later model decisions; tools on one server may affect use of tools on another. Review tool names, descriptions, and schemas; monitor definition changes; treat tool responses as untrusted data before they re-enter model context.
Confused-deputy behavior and excess privilege A server may use its own broad authority instead of the requesting user’s authority. Excessive OAuth scopes or reused credentials can increase the impact of a compromised server or manipulated agent. Grant minimum permissions per server and tool, scope credentials, and check requester and session identity when authorizing actions.
Injection into downstream systems Untrusted arguments or tool outputs may reach SQL, shell commands, filesystem paths, or remote URL fetchers, creating risks such as command injection or SSRF. Validate inputs and outputs, avoid raw commands and unsanitized paths, and restrict URL fetching to appropriate allowlists.
Supply-chain compromise Malicious or compromised packages, dependencies, typosquatting, or post-install changes can alter server behavior or definitions. Review source and definitions, verify package integrity, scan dependencies, and monitor for changes.
Weak transport, authentication, or operations Unauthenticated remote endpoints, exposed credentials, replay or tampering, inadequate limits, or weak audit coverage can undermine a deployment. Authenticate remote endpoints, use TLS, protect credentials, apply rate limits and timeouts, and log tool invocations and context changes with secrets redacted.
Unsafe runtime boundaries A local server with broad filesystem or network access can expose resources beyond the task it serves; compromised execution may escape intended limits. Run local servers with narrowly limited filesystem and network access, preferably in sandboxes, and separate sensitive servers from general-purpose ones.

These categories are risks, not measurements of how often incidents occur. The OWASP risk lists identify failure modes and mitigations; they do not establish an MCP-specific incident rate or loss figure.

How to secure an MCP server and its tools

  1. Inventory the workflow. Record the host and client, every connected server, the tools and external services involved, the data each can read or change, and the identity under which actions run. Include downstream tool calls, not only the first server connection.
  2. Reduce capabilities before connecting. Enable only the servers and tools needed for the use case. Give each server and tool the narrowest practical permissions; isolate credentials rather than reusing a broad credential across unrelated integrations.
  3. Review and monitor tool interfaces. Inspect names, descriptions, parameter schemas, and behavior. Treat changes after approval as changes to the trust boundary and re-review them before relying on the altered definition.
  4. Keep untrusted content from becoming authority. Treat tool results, retrieved documents, and extracted text as data rather than instructions. Validate and sanitize responses before feeding them back into model context or passing them to another tool.
  5. Constrain data paths and execution. Validate parameters before they reach SQL, shells, paths, or URL-fetching components. Restrict filesystem and network access for local servers; use appropriate URL allowlists for fetchers; and sandbox execution where feasible.
  6. Protect remote connections and credentials. Authenticate remote endpoints, use TLS for remote connections, store credentials securely, and apply rate limits and timeouts. Transport protections do not replace application-level authorization or safe handling of tool inputs and outputs.
  7. Put consequential actions behind informed approval. Require explicit confirmation for sensitive, destructive, financial, or data-sharing actions. Show the complete proposed action and parameters to the approver, rather than asking for a generic approval detached from what the tool will do.
  8. Make behavior observable. Record tool invocations and relevant context changes, with secrets redacted. Monitor for unexpected calls, permission changes, and altered tool definitions so operators can investigate and revoke access when behavior departs from expectations.

Choose controls according to deployment and action risk

There is no single configuration established as correct for every MCP threat model. Assess the deployment across the following dimensions and make controls stricter as the potential impact of a tool call rises:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  • Connection exposure: distinguish local stdio servers from remote HTTP exposure. Remote services need authenticated endpoints and TLS; local execution still needs restricted filesystem and network access.
  • Action reversibility: a read-only lookup differs from deleting records, changing access, transferring money, or sharing data. Use explicit human confirmation for sensitive or destructive actions.
  • Identity and scope: determine whether a server acts for the requesting user or with its own authority, and whether credentials and permissions are isolated per server and tool.
  • Definition and source trust: assess package provenance and dependency integrity, and decide how tool definitions are reviewed and monitored for changes.
  • Data handling: trace where inputs, outputs, retrieved content, and intermediate context can flow, including across tasks, users, agents, and sessions.
  • Operational visibility: verify that rate limits, timeouts, and audit records are sufficient to detect unexpected behavior and support response without recording secrets.

What the 2026 MCP specification update changes—and what it does not

The MCP maintainers’ announcement for the 2026-07-28 specification, published July 28, 2026, describes authorization hardening and a move from Dynamic Client Registration (DCR) toward Client ID Metadata Documents. The announcement says authorization servers should return the RFC 9207 iss parameter and clients must validate it before redeeming an authorization code; credentials are bound to their issuing authorization server; and DCR is formally deprecated in favor of Client ID Metadata Documents while remaining available for backward compatibility.

These are protocol authorization measures, not defenses against a model being steered by malicious content or a server being granted excessive capabilities. Confirm the versions and migration guidance for the specific client and server you deploy before changing authorization behavior; the announcement alone does not establish that every implementation has adopted the update.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Use OWASP guidance as a development and operations reference

OWASP’s A Practical Guide for Secure MCP Server Development, dated February 16, 2026, is aimed at software architects, platform engineers, and development teams. Its focus on delegated permissions, dynamic tool architectures, and chained calls is directly relevant when reviewing how a server’s capabilities fit into an agent workflow. The OWASP Cheat Sheet and Top 10 provide complementary risk and operational guidance; use them to structure threat modeling and review rather than as a substitute for checking the actual implementation.

Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.