文章总结: 文章介绍了MCP(ModelContextProtocol)服务器面临的安全风险,如提示注入、工具中毒和令牌盗窃等,并提供了相应的安全工具解决方案。文章指出,无论企业如何部署MCP服务器,都需要验证授权、实施细粒度访问控制和记录日志。文章将MCP安全工具提供商分为三类:超大规模云服务商(如AWS、Microsoft和GoogleCloud)、主要平台供应商(如Cloudflare、PaloAltoNetworks等)和初创公司(如Acuvity、Akto等),每类都提供了不同的MCP安全解决方案。
综合评分: 87
文章分类: 云安全,应用安全,安全工具,安全建设,解决方案
Tools, um MCP-Server abzusichern
原创
老兵
网安守护
2025年12月10日 15:03
北京
Tools to Secure Your MCP Servers
Using MCP servers is trending — and risky. Meet those risks with the right tools.
Whatever MCP servers a company deploys, for whatever purpose, “insecurity” should be left at the door.
Gorodenkoff | shutterstock.com
Model Context Protocol (MCP) connects AI agents to data sources and is rapidly gaining traction in the enterprise. Unfortunately, MCP is not free of security holes, as discoveries involving SaaS vendor Asana and tech giant Atlassian have shown.
Since then, progress has been made on MCP security. The core protocol now supports OAuth, third-party auth servers, and identity-management systems, and an official MCP Registry listing safe, publicly available servers has been launched.
Still, gaps remain that can be exploited for all kinds of cyber-mischief—prompt injection, tool poisoning, token theft, cross-server attacks, or tampered messages, to name a few. In short, any organization that wants a competitive edge when building agentic-AI systems must work hard to keep sensitive data from leaking. Fortunately, plenty of tools promise to help.
In this article you will learn:
- • What security tools should do for MCP
- • Which offerings are worth a look
What MCP-security solutions should deliver
Whether a company:
- • Connects its own AI agents to third-party MCP servers
- • Connects its own MCP servers to third-party agents
- • Or keeps everything in-house
the dangers of data leaks, prompt injection, and other threats are the same. That means organizations must verify authorizations, implement fine-grained access controls, and log everything. Those requirements translate into the following feature set for MCP-security tools:
- • MCP-server discovery. Employees can download and spin up MCP servers in minutes. Scanning services find every “shadow” instance across the enterprise.
- • Runtime protection. AI agents talk to MCP servers in natural language. Security tools must monitor that traffic for prompt-injection and other run-time attacks.
- • Auth & access controls. MCP now supports OAuth, but that is only a first step. Look for built-in Zero-Trust and least-privilege frameworks.
- • Logging & observability. Collect MCP logs, alert on policy violations, capture compliance data, and pipe everything into your existing security stack.
MCP-security offerings
We have grouped vendors into three categories. The list is not exhaustive.
Hyperscalers
If you are all-in on one cloud, the hyperscaler’s own MCP tooling is the easiest on-ramp.
- • Amazon Web Services introduced its agentic-AI platform in mid-2025. Amazon Bedrock AgentCore includes a multi-protocol gateway (MCP among them), identity management, and observability.
- • Microsoft ships a baseline Azure MCP Server with Azure Key-Vault support. Azure AI Foundry Agent Service and Azure API Management also speak MCP. The open-source Agent Framework adds prompt-injection defenses.
- • Google Cloud announced the MCP Toolbox for Databases in early 2025 with built-in auth and observability, plus a reference architecture for locking down remote MCP servers.
Major platform vendors
- • Cloudflare’s MCP Server Portals (part of Cloudflare One) let companies centralize and monitor MCP connections under a single Zero-Trust umbrella.
- • Palo Alto Networks plays two cards: Prisma AIRS, an intermediary MCP server that sits between agents and upstream servers to block malicious content, and MCP Security, a Cortex Cloud WAAS module that inspects MCP traffic at the network edge.
- • SentinelOne gives visibility into the entire MCP interaction chain via its Singularity Platform, issuing alerts and automated incident response for on-prem or remote MCP servers.
- • Broadcom has announced MCP-security functions for VMware Cloud Foundation to harden agent-based workflows.
Start-ups
- • Acuvity’s platform claims full-stack MCP protection via least-privilege execution, immutable runtimes, continuous vulnerability scanning, auth, and threat detection.
- • Akto, an API-security start-up, offers an MCP-security platform with discovery, security testing, monitoring, and threat detection.
- • Invariant Labs provides the open-source MCP-Scan for static analysis and real-time monitoring, plus a commercial proxy called Guardrails that enforces user-defined policies between agents and MCP servers.
- • Javelin’s AI Security Fabric scans MCP servers for risk and inspects data requests.
- • Lasso Security supplies an open-source MCP Gateway that handles configuration, life-cycle management, and message sanitization to strip sensitive data.
免责声明:
本文所载程序、技术方法仅面向合法合规的安全研究与教学场景,旨在提升网络安全防护能力,具有明确的技术研究属性。
任何单位或个人未经授权,将本文内容用于攻击、破坏等非法用途的,由此引发的全部法律责任、民事赔偿及连带责任,均由行为人独立承担,本站不承担任何连带责任。
本站内容均为技术交流与知识分享目的发布,若存在版权侵权或其他异议,请通过邮件联系处理,具体联系方式可点击页面上方的联系我。
本文转载自:网安守护 老兵《Tools, um MCP-Server abzusichern》