Skip to content

MCP security: protect every tool list, call and response on your own servers.

MCP security is the practice of controlling what passes between an AI agent and the tools it reaches through the Model Context Protocol. The risk is rarely a malformed request. It is an instruction: hidden in a tool's description, planted in a tool's response, or introduced when a tool changes after it was approved. Cyron AI Security catches all three on your own infrastructure.

What can go wrong in MCP

Seven attacks matter most. Each one arrives as a valid, authorised exchange, so firewalls, API gateways and API security wave it through. Each one has a detector built to catch it.

Attack What happens The detector that catches it
Tool poisoning A tool's description hides instructions for the agent, which obeys them in calls that look authorised Tool-description poisoning, backed by the hidden-instructions detector for invisible and look-alike characters
Rug-pull A tool you approved changes its definition later, so the agent calls something nobody reviewed Rug-pull
Tool shadowing A malicious tool takes a name almost identical to a trusted one, and the agent picks the wrong tool Tool shadowing
Output poisoning A tool's response carries instruction-shaped text that the agent reads as a command Output poisoning
Secrets in tool arguments The agent passes a cloud key, a token or personal data to a tool as an ordinary parameter Secrets and personal data in tool arguments
Cross-server exfiltration Data read from one tool server reappears in a call to another, within one agent session Cross-server exfiltration
Confused deputy A planted instruction makes the agent act beyond its caller's authority Confused deputy

Every finding carries its class from the OWASP Top 10 for LLM Applications (2025) or the OWASP Top 10 for Agentic Applications (2026). For one attack worked through from description to data loss, read Tool poisoning, explained.

How Cyron AI Security inspects MCP

Cyron AI Security inspects MCP over Streamable HTTP: tool lists, tool calls and tool responses, including streamed responses. Each part of the exchange is read for the attacks that live in it.

Tool lists

Checked for poisoned descriptions, hidden instructions, look-alike names and permissive or unsigned schemas. Each definition is recorded, so a later change is caught as a rug-pull.

Tool calls

Arguments are checked for secrets and personal data, and for oversized or encoded values typical of data being smuggled out. Data carried over from another tool server is caught too.

Tool responses

Checked for instruction-shaped text, and for responses that break the schema the tool declared.

Malformed or ambiguous messages

Messages crafted to confuse parsers are refused or flagged.

Detection is deterministic. The same exchange always gets the same verdict, and every verdict can be explained. Credentials seen in traffic are never written to disk.

Block by threat class and severity

Detect everything. Block only what you name. You choose the threat classes to block and the severity at which blocking starts. Everything else is allowed and recorded, and blocked calls leave evidence too.

Here is the result with Cyron AI Security, running as a gateway, set to block sensitive-information disclosure at high severity.

Verified result, gateway role: sensitive-information disclosure blocked at high severity

Want personal data blocked too? Lower the severity to medium.

Tool call carrying Result
AWS access key Refused. The tool server received it zero times
Email address Allowed and recorded
14-digit order number Correctly ignored: it is not a card
Phone number Allowed
Ordinary text Allowed

MCP gateway or kernel sensor: your choice

Run Cyron AI Security as an MCP gateway in front of your MCP servers, where it refuses malicious calls before they reach the tool. Or run it inside Cyron On-Premise, where iris, the eBPF kernel agent, captures agent traffic, your agents need no changes, and sources are blocked at the kernel.

What Gateway Kernel sensor, inside Cyron On-Premise
How traffic reaches it Agents call the gateway, one route per registered tool server The iris kernel agent copies agent traffic. Nothing is re-routed
Who enforces The gateway refuses the call with HTTP 403 before the tool server is reached For the threat classes you chose, Cyron API Security blocks the source at the kernel
Where you see it Findings in Cyron AI Security Findings, plus incidents and SIEM events in Cyron API Security
Works with Cyron API Security On its own or alongside Together, as one loop

Both roles are self hosted. Cyron AI Security installs on a Linux host with a container runtime inside your network. Your MCP traffic is analysed on prem, and it stays there. It is licensed by a signed licence file, issued for your deployment, with no call-home.

Is MCP safe to use?

MCP is as safe as the servers you connect and the checks you put around them. Treat every tool description and every tool response as input to inspect, and use a security gateway that reads what passes.

How do I secure my MCP server?

Require authentication on every server. Review and approve each tool, and treat any later change as an incident. Inspect tool arguments for secrets and tool responses for instructions. Log every call.

Government guidance now covers MCP directly. For a fuller list of controls, read the NSA's MCP security guidance (May 2026).

Do MCP servers require authentication?

The specification defines authorisation for servers reached over HTTP, but it does not force every server to use it. Scans of public servers have found many with none. Require it on every server you run.

What is an MCP gateway?

An MCP gateway is a service that sits between AI agents and MCP tool servers. Agents call the gateway, and it forwards each exchange to the right server. A security gateway also inspects what passes and can refuse it. You need one once several agents and servers are in use, or when someone must be able to show what was called and what was refused.

Do I need to change my agents?

Not with the kernel sensor. Inside Cyron On-Premise, iris captures agent traffic with no change to your agents, and the source is blocked at the kernel.

Does it need a GPU?

No. Cyron AI Security needs no GPU. It runs fully air-gapped, with no call-home, so it fits air gapped networks with no internet connection at all.

Evaluate it against your own agents

Cyron AI Security installs on a Linux host inside your network. Tell us which MCP servers and agents you run, and we will set up an evaluation on your servers.