MCP Threat Guide Turns Six Attack Classes Into Enterprise Controls
What happened
The Agentics released the Enterprise MCP Guide 2026 on October 5, 2026. It provides the most detailed public taxonomy to date of attack classes targeting the Model Context Protocol (MCP). MCP is the standard that lets AI agents connect to and act within enterprise tools such as email, databases, code repositories, and payment systems. The guide names six attack classes. Tool poisoning: a malicious tool description tricks an agent into taking harmful actions. Schema poisoning: the list of available tools is tampered with. Tool shadowing: a malicious tool quietly overrides a legitimate one. Command injection: attackers embed instructions in content the agent processes. Shadow servers: unauthorized MCP servers are added to an agent's environment without approval. Context oversharing: agents expose more data than a task requires. Recommended controls include per-agent allowlists that restrict each agent to only the tools it genuinely needs. Identity binding ties each agent's actions to a verified account. Centralized MCP gateways log all tool use. Human approval is required before agents can delete data, send communications, or take other irreversible actions. The guide arrives as 68 MCP Server CVEs in one month confirmed the attack surface is already being exploited at scale.
Why it matters
- ·Most enterprise agent deployments have no inventory of active MCP servers and no per-agent tool allowlisting. A single compromised or malicious server can reach any system the agent has credentials for. The Five Eyes Agentic AI Security Guidance and the NIST AI Risk Management Framework both treat least-privilege access as a baseline requirement. Tool-layer enforcement is absent from most programs today.
- ·Context oversharing and shadow servers create data exposure and unauthorized access. These issues can trigger breach notification obligations under the General Data Protection Regulation (GDPR) and equivalent laws. Most incident response playbooks were not written with agent-initiated data leakage in mind. A breach caused by an MCP server exposing data beyond task scope may not surface in traditional monitoring until significant harm has occurred.
- ·Human approval gates for destructive or irreversible agent actions are now cited by multiple guidance sources as baseline governance. The guide confirms that without technical enforcement at the MCP layer, a policy requirement is not a control. Compliance teams that have documented human-in-the-loop policies without verifying technical enforcement carry audit and regulatory exposure.
Governance controls affected
What to do now
- ☐Ask your engineering or IT team to produce a complete list of every MCP server currently connected to any AI agent in your environment, including servers added by individual teams or developers without central approval.
- ☐Verify that each AI agent is restricted to only the specific tools it needs for its assigned tasks. If a single agent can reach email, databases, and payment systems simultaneously, that is a control gap requiring remediation.
- ☐Confirm that your human approval gate for agent actions is technically enforced at the tool layer and not solely a policy statement. Ask the team to demonstrate that an agent cannot delete records or send external communications without a logged human sign-off.
- ☐Check whether your AI incident response playbook covers agent-initiated data exposure through tool misuse or context oversharing, and update it if MCP-specific scenarios are absent.
- ☐Add MCP servers to your third-party AI vendor due diligence process: require the same security documentation, access scope review, and update notification obligations from MCP server providers that you require from AI model vendors.
What to watch next
The CIS MCP Benchmark has already set a 55-point audit baseline for agent tool governance. Regulators referencing the Five Eyes Agentic AI Security Guidance are beginning to cite tool-layer controls in supervisory expectations. Compliance teams should monitor whether the EU AI Office incorporates MCP-specific controls into its high-risk AI enforcement guidance under the EU AI Act (Regulation (EU) 2024/1689). They should also watch for the MAS Guidelines on Artificial Intelligence Risk Management to finalize. That guidance is expected to address agentic tool access in financial services contexts. The South Korea Drafts Agentic AI Security Rules development signals that MCP governance is moving toward binding requirements in multiple jurisdictions.
Stay ahead of stories like this
Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.
Recent issues
- AI agents this week destroyed backups at machine speed, leaked sensitive data without developer approval, and drew federal scrutiny that may extend liability to every enterprise deploying them.1 Oct
- A vulnerability that bypasses approved-plugin controls, new criminal liability for executives, and a landmark safety-disclosure framework all point to one conclusion: AI systems are outpacing the controls organizations have built around them.23 Sept
Free every Thursday. Unsubscribe anytime.
