Rendered Source Note

Model Context Protocol - Security Best Practices

Generated HTML view. Markdown remains canonical.

Model Context Protocol - Security Best Practices

Type: official-doc Tier: 1 (Official Doc) Author(s): Model Context Protocol Date: 2025-06-18 URL: https://modelcontextprotocol.io/specification/2025-06-18/basic/security_best_practices Accessed: 2026-06-02

Why This Source Matters

This is the primary source for MCP-specific security risks. It extends the Project 06 path-containment lesson into a distributed trust boundary: a host may launch or connect to external servers that can expose tools, read resources, and touch local or remote systems.

Key Claims

Relevant To

Notes

This source should anchor the failure analysis for an MCP elective: unsafe server launch commands, over-broad filesystem access, missing input validation, and tool-result poisoning are not edge cases.