MCP security topic hub

MCP security articles for scanners, gateways, authorization, and runtime controls

Use this hub for Model Context Protocol security research: server review, authorization, OAuth pitfalls, gateway controls, scanner-to-runtime coverage, tool poisoning, and runtime audit evidence.

· 2 articles · 1 guides

Search questions this hub answers

What is MCP security?

How do you secure MCP tool calls?

What should teams use after MCP-Scan-style scanner review?

How do MCP authorization and runtime permission checks fit together?

11 min read

NSA MCP Security Guidance: What It Means for AI Agents

NSA, CSA, IETF, and official MCP guidance translated into runtime controls for AI agents: trust boundaries, identity, tool validation, execution checks, and audit evidence.

MCP SecuritySecurity GuidanceAI Agent Security
12 min read

MCP Tool Poisoning: Runtime Defense for AI Agents

MCP tool poisoning explained: poisoned tool descriptions, schemas, metadata, and results; where scanners help; and why runtime dispatch and result checks still matter.

MCP SecurityTool PoisoningRuntime Security

Guides for this topic

Primary source page

For a concise definition and product-level framing, start with MCP security product page. The articles above expand the surrounding search intents and link back to the canonical Clawmont topic page.