The situation
An MCP server turns what an agent wants to do into actions: reading files, querying systems, sending messages. Installing one is closer to giving a contractor access than to adding a library. Before the agents went live, the client's security team wanted to know what each server could read, write and send, and under which conditions it could be used.
What we checked
Every server went through the same checks we describe in how we review an MCP server:
- every tool, and what it can read, write and send
- tool output treated as untrusted input, so a document cannot instruct the agent
- permissions enforced by the credential, not by convention
- where secrets live, and whether the model can ever see them
- which hosts the server can reach
- pinned versions and a known publisher
- human approval for anything irreversible
- logs that let you replay what happened
What kept coming up
Servers that had nothing else in common failed on the same conditions. This is where they sat:

