MCP server security: what to check before you connect one
MCP servers give your agent new tools and new reach. The trust, credential and permission questions to ask before you connect one, with a checklist.
Blog
Clear, practical pieces on application and AI-agent security — the kind of thing we wish existed when we were setting this up ourselves.
$ ls blog/ ✓ mcp-server-security ✓ secrets-in-git-history ✓ ai-code-review-fewer-false-positives ✓ securing-ai-agent-setups ✓ what-is-prompt-injection $
MCP servers give your agent new tools and new reach. The trust, credential and permission questions to ask before you connect one, with a checklist.
A removed secret still lives in git history. Why scanning only the working tree misses leaks, and what to do when a credential has already been committed.
Security scanners are thorough and noisy. How an LLM review pass on top of proven scanners keeps coverage while surfacing the findings that matter.
Agents, skills, memory, and MCP servers each add attack surface. A practical, defensive checklist for reviewing an LLM-agent setup in a code repository.
What prompt injection is, why it differs from SQL injection, and the practical patterns that keep untrusted input from hijacking your LLM agents.