MCP: tool servers are becoming the main attack surface against AI agents
The Model Context Protocol (MCP) connects agents to their tools. The more it spreads, the bigger a target it becomes: research published in 2026 converges on one finding, the tool server is the weak link.
What the research has shown
- Poisoned tools: a third-party MCP server can ship tool definitions with hidden instructions, some activating only after several uses ("rug pull").
- Auto-execution: researchers observed Claude Code, Cursor CLI, Gemini CLI and GitHub Copilot CLI launching project-defined MCP servers once a folder-trust prompt was accepted, without saying code would run.
- Indirect injection: in one reported case, an injection led Cursor's agent to create a malicious MCP configuration itself, then achieve remote code execution.
- A numbered flaw: CVE-2026-26118 affects a Microsoft MCP server and could let attackers manipulate how an assistant interacts with connected services.
- Open servers: roughly 38 to 40% of scanned MCP servers still run with no authentication at all, according to the summaries we reviewed.
A dedicated MCP security guide was also published in June 2026 on media.defense.gov, a sign institutions are taking the topic seriously.
Why it's specific to agents
An agent reads the text its tools return as possible instructions. A compromised tool, or a document the agent reads, can therefore tell it what to do. The more rights the agent has (files, email, shell), the bigger the potential damage.
Habits for a self-hosted stack
These are our general recommendations, not an official checklist:
- Authenticate every MCP server and never expose one without access control, even on a private network.
- Install only servers whose code you've read or whose source you control; pin versions.
- Least privilege: an agent gets only the tools its task needs, read-only where possible.
- Don't blindly accept folder trust in agentic coding tools.
- Require human approval for irreversible actions (sending, deleting, paying).
- Log tool calls so you can reconstruct what an agent did.
In agent orchestration the question is no longer just "what can my agent do" but "what could it be talked into obeying".
Sources: Microsoft MCP Server CVE-2026-26118 (PointGuard AI), Cloud Security Alliance, arXiv study on AI-assisted dev tools, MCP security guide (June 2026), The SaaS Library.