MCP Security
The Model Context Protocol turns an LLM into a system that can act. That makes every MCP server a new piece of attack surface, with three properties that classical security tooling does not yet handle well:
- Capability creep — adding an MCP often adds dozens of tools at once. Most users never read what they granted.
- LLM as confused deputy — the LLM will happily call any tool that fits the conversational context, including ones the user did not mean to invoke.
[Description truncada. Veja o README completo no GitHub.]