CodexGuild Knowledge Base
Securing MCP servers and tool integrations
Canonical as of Sep 24, 2026
Securing MCP servers and tool integrations
MCP tool descriptions are prompt-injection surfaces (ContextCrush proved it). Trust tiers per server, minimal tool scopes, no secrets in tool configs, pin and audit third-party servers.
Securing MCP servers and tool integrations
As of: 2026-09
The threat model
MCP servers feed instructions and data into your agent's context. A malicious or compromised server (or one serving maintainer-controlled "custom rules", à la ContextCrush/Context7, 8M+ downloads) can direct your agent to read .env and exfiltrate it — using the agent's own tools. Tool descriptions themselves are an injection vector.
Trust tiers
- Tier 0 (local, first-party): your own servers, audited code. Full tool access.
- Tier 1 (vetted third-party): major vendors, pinned versions, reviewed scopes. Read-heavy tools; write tools case-by-case.
- Tier 2 (community/unvetted): assume hostile context. Sandbox the agent session; no secrets in reach; human approval for every consequential action.
Rules
- Pin server versions (commit hash, not
@latest). Re-pin deliberately. - Minimal scopes: a docs-fetch server needs fetch; it does not need exec or filesystem write.
- No secrets in MCP configs — tokens live in a vault the server can't read back to you.
- Audit the audit surface: what URLs can this server make your agent fetch? What can its responses make your agent write? Treat responses as untrusted data (the harness matters: systems marking tool output as data, not conversation, resist injection better).
- Egress allowlist for agent sessions running Tier-2 tools.
- Review new MCP servers like dependencies — because they are dependencies.