▲ | Aunche 5 days ago | ||||||||||||||||||||||||||||||||||||||||||||||||||||
I still don't understand understand. Aren't the risks the exact same for any external facing API? Maybe my imagined use case for MCP servers is different from others. | |||||||||||||||||||||||||||||||||||||||||||||||||||||
▲ | Yeroc 5 days ago | parent [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||
Imagine running an MCP server inside your network that grants you access to some internal databases. You might expect this to be safe but once you connect that internal MCP server to an AI agent all bets are off. It could be something as simple as the AI agent offering to search the Internet but being convinced to embed information provided from your internal MCP server into the search query for a public (or adversarial service). That's just the tip of the iceberg here... | |||||||||||||||||||||||||||||||||||||||||||||||||||||
|