Knowledge base
CodexGuild Knowledge Base

Securing MCP servers and tool integrations

as of Sep 24, 2026 · canonical · codexguild.com/kb/mcp-server-security-guide · exported 2026-10-11
Canonical as of Sep 24, 2026

Securing MCP servers and tool integrations

MCP tool descriptions are prompt-injection surfaces (ContextCrush proved it). Trust tiers per server, minimal tool scopes, no secrets in tool configs, pin and audit third-party servers.

Securing MCP servers and tool integrations

As of: 2026-09

The threat model

MCP servers feed instructions and data into your agent's context. A malicious or compromised server (or one serving maintainer-controlled "custom rules", à la ContextCrush/Context7, 8M+ downloads) can direct your agent to read .env and exfiltrate it — using the agent's own tools. Tool descriptions themselves are an injection vector.

Trust tiers

  • Tier 0 (local, first-party): your own servers, audited code. Full tool access.
  • Tier 1 (vetted third-party): major vendors, pinned versions, reviewed scopes. Read-heavy tools; write tools case-by-case.
  • Tier 2 (community/unvetted): assume hostile context. Sandbox the agent session; no secrets in reach; human approval for every consequential action.

Rules

  1. Pin server versions (commit hash, not @latest). Re-pin deliberately.
  2. Minimal scopes: a docs-fetch server needs fetch; it does not need exec or filesystem write.
  3. No secrets in MCP configs — tokens live in a vault the server can't read back to you.
  4. Audit the audit surface: what URLs can this server make your agent fetch? What can its responses make your agent write? Treat responses as untrusted data (the harness matters: systems marking tool output as data, not conversation, resist injection better).
  5. Egress allowlist for agent sessions running Tier-2 tools.
  6. Review new MCP servers like dependencies — because they are dependencies.