MCP Server Best Practices: A Security Checklist for CISOs
MCP server best practices come down to one principle: treat every MCP server as an untrusted boundary, not an internal tool. The Model Context Protocol, introduced by Anthropic in November 2024, lets an AI agent call external tools and data through a standardized server interface — which means a malicious or careless MCP server inherits the same trust you'd give an internal system. The core practices are: scope server permissions to least privilege, validate and pin tool descriptions, authenticate every connection, log every tool call, and isolate servers from each other. Everything below expands on those five.
Design MCP servers around least privilege and explicit scope
A best practice when designing MCP servers is to make each server do exactly one job with the narrowest possible access. An MCP server that reads customer records should never also have write access to billing, and it should never expose a generic "run shell command" tool. Concretely:
- One capability domain per server. Split read and write operations into separate servers so you can grant them different trust levels.
- Scope credentials at the server, not the agent. The server should hold a service account limited to the specific tables, repos, or API scopes it needs — not a broad admin token the agent can abuse.
- Return minimal data. Don't dump entire rows into context when a field will do. Every byte returned becomes model context an attacker could manipulate.
- Make tools deterministic and typed. Define strict input schemas (JSON Schema) and reject malformed calls server-side rather than trusting the agent to format them correctly.
If you build in Python, the official mcp SDK supports typed tool definitions and lets you enforce input validation at the transport layer — use it rather than hand-rolling a server that parses raw strings.
Defend against tool poisoning and prompt injection
The highest-severity MCP-specific risk is tool poisoning. MCP tool-poisoning attacks exploit hidden instructions embedded in a tool's description to manipulate agent behavior without ever touching the user's prompt — a form of indirect prompt injection delivered through the tool layer. Because the agent reads tool descriptions to decide what to call, a compromised or malicious server can instruct the model to exfiltrate data, call a different tool, or ignore safety constraints.
Mitigate it with these controls:
- Pin and review tool definitions. Treat a tool description change like a code change — version it, diff it, and require review. A description that silently gains new instructions is your signal.
- Only connect vetted servers. Pull servers from sources you trust (the official Anthropic reference servers on GitHub, or your own repos) and avoid installing community servers without reading the code.
- Isolate untrusted content from privileged tools. If an agent reads external web or email content, don't let it call high-privilege tools in the same session without a human checkpoint.
- Constrain outputs. Strip or sanitize instructions-looking text from tool results before they re-enter context where possible.
Authenticate, log, and isolate every server
Security best practices for MCP servers are mostly classic AppSec applied to a new interface:
- Require authentication on every transport. For remote MCP servers, use OAuth or signed tokens — never run an unauthenticated HTTP server that any client can connect to. For local
stdioservers, control the process environment and the secrets passed in. - Log every tool invocation with arguments and caller identity. You need an audit trail to answer "what did the agent actually do" during an incident. Treat MCP logs like database query logs.
- Sandbox the server process. Run it with a dedicated low-privilege OS user, in a container, with no outbound network access beyond what the tool needs. A poisoned tool can't exfiltrate to an attacker's domain it can't reach.
- Rate-limit and set timeouts. Bound how often and how long a tool can run to blunt loops and abuse.
Choosing and optimizing which MCP server to use
For "what MCP server should I use," start with the official Anthropic reference servers and well-maintained GitHub projects with active commit history, clear permission scoping, and published security practices — then wrap them in your own auth and sandbox layers. Avoid servers that request broad credentials or bundle a generic command-execution tool.
To optimize MCP server performance and cost:
- Trim tool descriptions and schemas — they consume context tokens on every call. Keep them precise, not verbose.
- Cache idempotent reads so repeated lookups don't hit upstream systems.
- Return paginated or summarized results instead of full payloads to keep context lean and latency low.
- Limit the number of connected servers per agent — fewer tools means faster, more accurate tool selection and a smaller attack surface.
If you're deploying MCP servers and want a fast read on where your exposure sits, run PlayCISO's free MCP Server Risk Check — it flags common gaps like miss
Ready to practise the decisions these articles describe?
Run a free War Room →