Most MCP incidents worth imagining reduce to one shape. A server, or a set of them, lets the model read content an attacker can influence and act with authority — send, delete, pay, push. Each half is manageable on its own. Together they hand your permissions to whoever writes the most persuasive document your model reads. Design deployments so that combination needs a human in between, and most of the scare stories stop applying to you.
Why this page is the site
Explainers of MCP are everywhere; disciplined adoption guidance is not, and that gap is where teams get hurt. This site's bet matches our network's pattern: the durable value is a checklist that stays true as the spec evolves. The moving details belong to modelcontextprotocol.io.
Evaluation questions
What is the prompt-injection risk with MCP servers?
A model reading attacker-influenced content — a webpage, an email, a document — can be steered into calling tools in the attacker's interest. MCP servers are those tools. The mitigations are architectural, not vibes: least-privilege scopes per server, and human confirmation on destructive or exfiltrating actions. Keep read-tools separate from write-tools. Treat any server that both reads untrusted content and holds write power as the highest-risk combination you can deploy.
What should I check before adopting a community server?
Six checks. First, provenance: who maintains it, and is the vendor involved. Then the code volume you can actually review, against what it claims to need. Check the permissions and credentials it requests against least privilege, plus its transport and auth story if it runs remote. Last, maintenance signals — recent commits, issue responsiveness, pinned dependencies — and a read of what the tool descriptions tell the model, because those descriptions are prompt-adjacent surface too.
How should teams roll MCP out safely?
Treat it like any capability with blast radius. Keep an allowlist of approved servers rather than a developer free-for-all, and scope credentials per server instead of sharing master keys. Log tool calls so incidents can be reconstructed, and put a review gate in front of any write-capable server. Teams that already run dependency review can extend that process. The only novel part is that the "caller" is a model that believes what it reads.