MCPAI SECURITY ENGINEERING

MCP least privilege

MCP tools should run with only the permissions needed for their advertised function.

WHY IT MATTERS

A narrow tool description can hide broad backend credentials.

ENTERPRISE EXAMPLE

A customer lookup tool connects using a database owner account that can read unrelated sensitive tables.

SECURITY DECISION

Which security control should be explicit?

REMEMBERAdvertised scope must match real backend privilege.
No uploads · No company data · No account required