MCP Security Risks Multiply With Each New Agent Connection

The New StackAbout 5 min readAug 24, 2025Watch original
THE SUMMARYAI-generated

Key Concepts:

  • API Security
  • MCP (Multi-Context Protocol) Security
  • LLM (Large Language Model) Security
  • Application Security Testing (AST)
  • AI-assisted Security
  • Agentic AI
  • Prompt Injection
  • Contextual Security
  • Shift Left/Shift Right Security
  • Adversarial AI
  • Guardrails

1. Introduction and Guest Speaker:

  • The discussion starts with a lighthearted exchange about energy levels and jury duty.
  • Sria Schneider, co-founder of Pint, is introduced as the guest speaker.
  • Sria expresses hope for peace and normalcy in Israel, where she is based.
  • The startup scene in Israel is described as being at its peak, particularly in cyber security and AI.
  • Sria mentions Pint has a US company with an Israeli subsidiary, and she spends a lot of time traveling to meet customers.

2. Trends in Tech Coverage:

  • Frederick discusses popular stories in tech coverage, highlighting command line agents like Cloud Code, Gemini CLI, and Kira from AWS.
  • The departure of GitHub's CEO, Thomas Dome, is noted as an unexpected event, raising questions about Microsoft's deeper integration with GitHub.
  • Research indicating that Cursor was more popular than GitHub Copilot among developers is discussed.

3. AI Tool Usage and Challenges:

  • Sria mentions that her company uses many AI tools internally.
  • She shares that a lead engineer wrote an article about the current state of AI tools being in a "brown field," where heavy use can waste time, and light use doesn't contribute much.
  • The lack of context in AI tools is highlighted, using the example of ChatGPT and Claude providing the same random number (47).
  • Sria draws an analogy between the development of AI coding tools and the shift from semi-autonomous to autonomous cars, noting that full autonomy isn't yet achieved.
  • She quotes the CEO of Lemonade, comparing the current AI revolution to the shift from horses to cars, emphasizing that security concerns often follow functionality.

4. Pint's Evolution from API Security to MCP and LLM Security:

  • Sria explains that Pint has evolved from focusing solely on API security to encompassing MCP and LLM security, all under the umbrella of application security.
  • She emphasizes that they haven't pivoted but rather expanded their focus to cover the evolving landscape of application development, from web to APIs to LLMs and now MCPs.
  • Pint aims to be a one-stop shop for automated application security testing, focusing on "hacking as fast as possible" to identify and fix vulnerabilities early in the development process.
  • Sria notes that many current issues are in data flows and business logic rather than the core code.

5. MCP Security Implications:

  • The discussion shifts to the security implications of MCPs, noting that APIs are deterministic, while MCPs are autonomous and undeterministic.
  • Sria shares findings from a research study on 281 real-world MCPs, revealing that the risk increases significantly when multiple MCPs work together.
  • She provides an example of connecting Gmail and code execution MCPs to Claude, demonstrating how Claude could be manipulated to write phishing emails and run malicious code.
  • Sria emphasizes that MCPs introduce a new attack surface and don't replace existing security concerns like API vulnerabilities and prompt injection.

6. MCP Attack Vectors and Security Plans:

  • Sria describes potential attack scenarios involving malicious MCPs accessing file systems and sending sensitive data via email.
  • She notes that organizations are only beginning to develop MCP security plans, and many are struggling to balance security with innovation.
  • The discussion touches on the challenges of balancing user experience with security, particularly the need for consent and authentication.
  • Sria points out that engineers have significant influence in organizations and prioritize innovation and functionality over security.

7. Autonomy vs. Security in AI Agents:

  • The conversation explores the tension between the autonomy of AI agents and the need for security.
  • Sria draws a parallel to the development of autonomous vehicles, noting that current implementations have many guardrails and limitations.
  • She suggests that the future will involve implementing more heuristic guardrails and safer models to enable more secure agentic systems.
  • The discussion touches on Google's agent-to-agent protocol (A2A), but Sria notes that customers are currently more focused on addressing fundamental API security issues.

8. Adversarial AI and the Security Race:

  • Sria discusses the use of AI by adversaries and the ongoing race between attackers and defenders.
  • She emphasizes that Pint plays the adversarial role to understand and automate attack strategies.
  • Sria acknowledges the potential for AI to be used for unethical purposes, such as deepfakes and misinformation.
  • She stresses the importance of putting the right guardrails in place and recognizing that everything is ultimately hackable.

9. Pint's Approach to Security:

  • Sria clarifies that Pint focuses on helping customers release secure software that is difficult to hack, rather than solely on detection in production.
  • She describes their approach as AI-assisted, where they strategically integrate AI to enhance specific aspects of their product, such as analysis, discovery, and remediation.
  • Context is emphasized as crucial, and Pint's API security testing is contextual, considering the traffic and usage patterns of APIs.
  • AI helps Pint understand the context of traffic and describe issues with business context, such as the impact on users.

10. Conclusion:

  • Sria concludes by reiterating that MCPs are evolving to be the new APIs but not replacing them.
  • She emphasizes that everything is application-centric, starting from code and evolving to business data flows, and application security should be treated holistically.
  • The hosts thank Sria for her insights and announce their upcoming live broadcast from the Open Source Summit in Amsterdam.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.