Work / Case · Agent security

An MCP security review that became the tool we use for clients.

A client was about to connect its AI agents to MCP servers with access to internal data and tools. We reviewed every server before rollout. The checks we ran became the MCP Trust Registry, the tool we now use to help clients secure their AI workflows.

Client
Anonymised, under NDA
Service
Agent and MCP security review
Scope
Every MCP server the agents could call
Led to
The MCP Trust Registry
8
checks on every MCP server the agents could call
6
risk areas in one schema, from identity to disclosure

The situation

An MCP server turns what an agent wants to do into actions: reading files, querying systems, sending messages. Installing one is closer to giving a contractor access than to adding a library. Before the agents went live, the client's security team wanted to know what each server could read, write and send, and under which conditions it could be used.

What we checked

Every server went through the same checks we describe in how we review an MCP server:

  • every tool, and what it can read, write and send
  • tool output treated as untrusted input, so a document cannot instruct the agent
  • permissions enforced by the credential, not by convention
  • where secrets live, and whether the model can ever see them
  • which hosts the server can reach
  • pinned versions and a known publisher
  • human approval for anything irreversible
  • logs that let you replay what happened

What kept coming up

Servers that had nothing else in common failed on the same conditions. This is where they sat:

MCP Trust Registry reads hereAI agentreads tickets, documentsand codeMCP serverfile and shell toolsMCP serverticket and data toolsMCP servercode and fetch toolsFiles and shellInternal systemsCode hostingAny host online123456MCP Trust Registry reads hereAI agenttickets, documents, codeMCP serverfilesMCP serverinternalMCP servercode, webFiles andshellInternalsystemsCodehostingAny hostonline123456
  1. Tool descriptions and tool output that carry instructions for the agent, or ask it for secrets
  2. Broad file access or a shell, with arguments passed straight to a process
  3. Tokens read from the environment and written to logs
  4. OAuth scopes far broader than the tools need
  5. Outbound access to any host where one API would do
  6. Unpinned versions, install scripts, downloads without a digest and packages that don't match their repository
  7. What the MCP Trust Registry reads: each server's package and metadata, without installing or running it
An AI agent calls three MCP servers, which reach files and a shell, internal systems, code hosting and any host online. Numbered markers show where the recurring conditions sat; a dashed outline marks what the MCP Trust Registry reads.

The client received the evidence for every finding and a concrete fix per server: a narrower token, an egress rule, a human approval step or a pinned version. Some servers stayed out until their publishers fixed them.

Why we built a tool

Checking every new server, and every new version of it, by hand does not scale. Public MCP registries help you find servers; they don't tell you what a server can do once your agent calls it. So we turned the checks into the MCP Trust Registry:

  • a deterministic scanner that reads a server's package and metadata without installing it, running it or calling its tools
  • evidence for every finding, with its source and what was redacted
  • one risk schema across identity, provenance, package hygiene, capabilities, behaviour and disclosure
  • reports that state what was observed and what it means for your policy, never a "safe" or "unsafe" label

We now run the registry for clients: on the MCP servers and agent tools in their AI workflows, before they go live and again when a server changes. An engineer checks every finding before it goes into a report. See a sample report.

This is the kind of work we do in agent and MCP security review. If you have a system like this, start a project.

Start a project

Tell us what has to work.

Describe the system and the deadline. We reach out within five days; the first call is free and confidential.


Or email hello@mochavi.com