Agent Security

    MCP Server Security

    Model Context Protocol servers are becoming the standard way agents reach your systems — and they are being deployed with default trust, no isolation and no review. Almost nobody in DACH covers this.

    Sound familiar?

    • Third-party MCP servers installed from a repository and trusted implicitly.
    • Tool descriptions themselves are model input — and therefore an injection surface.
    • Server processes run with broad local or network access on developer machines.
    • No provenance, pinning or review process for MCP server updates.

    What we do

    Server review

    Code, permissions, network reach and update path of every MCP server in use.

    Tool description hardening

    Treating tool metadata as untrusted input, because the model reads it.

    Isolation

    Sandboxing, network policy and credential separation per server.

    Supply chain policy

    Pinning, provenance checks and an approval path for new servers.

    Questions we get

    We only use MCP locally in the IDE. Still relevant?

    Especially then — developer machines hold the credentials that production does not.

    Do you review our own MCP servers too?

    Yes, both third-party and in-house servers.

    Tell us what's running in production.

    We'll tell you what we'd check first — and what we wouldn't bother with.

    Book a call
    Related
    More in Secure