MCP server security testing with evidence

MCP Server Risk Assessment

Review what an MCP server exposes, which identities and data it can reach, how tool output can influence an agent, what actions can execute, and what evidence supports a deployment decision.

Version-bound assessment and retest evidence Unknown is not a finding Observed failure required for a finding
Useful before connecting an MCP server to a real agent or expanding its authority Remote MCPLocal MCPDynamic toolsCustomer dataHigh-impact actions
What server risk testing should answer

Connecting successfully is not the same as being controlled.

An MCP server can sit across identity, authorization, tool discovery, untrusted tool output, secrets, external APIs and privileged actions. The assessment binds those capabilities to the exact server and agent version being reviewed.

01

Server trust

Who operates the server, how is its version or origin established, and can a package, marketplace entry or dependency change what the agent trusts?

02

Authorization

Are tokens intended for this server, are scopes minimal, are credentials isolated by issuer and environment, and can one identity cross a tenant or resource boundary?

03

Tool influence

Can tool descriptions, schemas, dynamic discovery or tool output place untrusted instructions into the model context and influence another privileged tool call?

04

Action authority

Can the agent write, delete, deploy, refund, message, change permissions or trigger downstream side effects without an exact policy or human approval boundary?

MCP risk assessment coverage

Test the boundaries that change what the server can cause.

Controls are evaluated in context. A risky capability can make a control applicable, but it does not become a vulnerability until an observed or reproducible failure supports a finding.

1
PROVENANCE

Server, package and dependency trust

Record the server identity, deployment origin, package or image version, external dependencies and how changes are detected before they reach the agent.

2
AUTH

OAuth, audience and scope

Review resource and audience binding, issuer validation, token storage, redirect handling, least-privilege scopes and separation between MCP and upstream API credentials.

3
TOOLS

Tool schemas and dynamic discovery

Check whether newly discovered or changed tools can expand authority silently, whether descriptions are treated as untrusted, and whether schemas constrain inputs and outputs.

4
INJECTION

Tool poisoning and prompt injection

Use authorised tests to see whether malicious or compromised tool output can steer the model toward restricted data, another tool or an unsafe action.

5
SECRETS

Credentials and data exposure

Review environment secrets, logs, tool arguments, returned content, file and network access, tenant boundaries and whether sensitive values can escape through tool calls.

6
APPROVAL

High-impact action integrity

For consequential actions, check that approval is bound to the exact tool, target, parameters, value and validity period and cannot be replayed after the approved action changes.

7
RUNTIME

Server-side enforcement

Verify that restrictions are enforced at the tool or policy boundary rather than relying only on model instructions, and that runtime decisions create reviewable evidence.

8
RETEST

Remediation and exact retest

Record the fix against the changed system version, rerun the original failure condition and preserve the result before a finding is closed or deployment advice changes.

Evidence model

What proves an MCP risk is controlled?

AgentRiskLayer separates what the owner says is configured from what inspection, controlled testing and runtime records actually demonstrate.

  1. 1
    DECLARE

    Exact server and agent scope

    Identify the server, protocol implementation, agent version, tools, identities, data, external services, network reach and approval model.

  2. 2
    OBSERVE

    Inspect the implemented boundaries

    Collect relevant configuration, tool definitions, authorization behavior, policy enforcement and privacy-safe evidence without treating claims as proof.

  3. 3
    TEST

    Run authorised failure tests

    Exercise defined scenarios for tool poisoning, prompt injection, privilege misuse, token or tenant boundary failures and high-impact action controls.

  4. 4
    DECIDE

    Finding, fix, retest, decision

    Create a finding only when the failure is observed or reproducible. Record remediation, rerun the exact test and use current evidence for proceed, hold or do-not-deploy decision support.

Example MCP attack path

A harmless-looking tool response tells the agent to call a privileged internal tool.

The security question is not whether the text looks malicious. It is whether untrusted tool output can cross a trust boundary and cause a privileged action. A controlled system should constrain tool responses where practical, isolate privileged actions, enforce permissions outside the model and require exact approval where impact warrants it.

Evidence rule FAILURE BEFORE FINDING

Potential attack path → applicable control → authorised test → observed result.

Tool output untrusted?
Control applies
Exploit not reproduced?
No finding yet
Failure reproduced?
Finding + remediation
Current MCP security context

Bind the review to the protocol behavior you actually run.

The MCP 2026-07-28 release moved the protocol core to stateless requests and added authorization hardening. Assessments should record the implementation and version in scope rather than assume all MCP clients and servers behave the same way.

Stateless requests

Current MCP requests can carry protocol, method, tool and client information per request. Gateways can therefore apply routing, authorization and metering to self-describing requests rather than depending on a protocol session.

Authorization hardening

Review issuer validation, credential isolation, resource and audience binding, step-up scope behavior and the exact authorization flow implemented by the client and server.

Known attack pattern

OWASP documents MCP Tool Poisoning, where malicious tool responses can inject instructions into an agent context and attempt to reach more privileged tools or data.

From free check to evidence

Start with the MCP agent you actually plan to deploy.

The free check qualifies the architecture and missing evidence. The one-off AI Agent Security Assessment unlocks the full report and customer-operated evidence, controlled-testing, remediation and retest workflows; only completed work is reported as performed.

QUALIFY

Free agent check

£0

Describe the MCP server, agent, tools, permissions and safeguards and get an initial risk view.

Start free
OPERATE

Runtime protection

From £29 /month

Ongoing runtime decisions, approvals, evidence retention and project workflows.

Compare plans
MCP security assessment FAQ

Questions before you connect a server to an agent

Is every MCP server automatically high risk?

No. Risk depends on the server's permissions, data, tools, external dependencies, agent authority and implemented controls. Capability alone is not a finding.

Does missing MCP information become a vulnerability?

No. Unknown, missing or inconclusive information remains an information gap. A finding requires an observed or reproducible failure.

Can you test tool poisoning?

Where the owner authorises the scenario and the environment is appropriate, controlled testing can check whether untrusted tool content can influence restricted actions. Production destructive testing is not implied.

What should be tested around OAuth?

Relevant tests can cover token audience and resource binding, issuer validation, scope boundaries, redirect handling, secret storage and separation between MCP credentials and upstream service credentials.

What evidence is useful?

Useful evidence can include versioned tool definitions, policy configuration, authorization behavior, inspection output, controlled test results, runtime decisions, human approvals and exact retest records.

Is this an MCP certification?

No. AgentRiskLayer Security Assessment is a proprietary assessment against the AgentRiskLayer Control Profile. It is not an accredited certification or a guarantee that a system is risk-free.

Assess one real MCP integration

Find out what the server can expose, what the agent can do and what evidence is still missing.

Start free. Findings require observed or reproducible failure evidence.

Start the MCP server risk assessment