MCP Channel Trust
The trust channel between an MCP client and server can carry malicious content, intercepted requests, or manipulated trust dialog, allowing an attacker to control agent behavior through the communication channel.
Exposure and failure modes
Observed exposure paths where generative AI connects language to data, identity, tools, permissions, or decisions before governance has enough grip.
The trust channel between an MCP client and server can carry malicious content, intercepted requests, or manipulated trust dialog, allowing an attacker to control agent behavior through the communication channel.
An attacker-controlled artifact reaches an AI coding agent through plugin resolution, symlink paths, model cache, or CI trigger, and executes with the agent's privileges.
An AI system can take actions that exceed its reliability, authorization, or oversight model.
AI systems call tools or APIs without sufficient validation, authorization, rate limits, or operational safeguards.
Untrusted instructions enter an AI workflow and compete with the system's intended authority.
Sensitive business, personal, regulated, or secret data moves through prompts, outputs, logs, retrieval, or connected tools.
Unapproved or unknown AI use removes visibility from data handling, identity, procurement, and incident response.