Artificial Intelligence - Model Context Protocol - Review of Real-World Security Threats
Abstract
Modern Artificial Intelligence (AI) infrastructures and Model Context Protocol (MCP) deployments face systemic security exposures as a result of autonomous agents interacting directly with external databases and tools. Protocol-level weaknesses, permissive access rights, and unverified third-party repositories allow attackers to execute prompt injection attacks, exfiltrate credentials, and manipulate tool metadata schemas. This paper examines security incidents across five primary domains: tool and server security, prompt and context security, data security and privacy, system and operational security, and authentication and identity security. Underlying root causes and effective mitigation strategies are explored through real-world case studies, including supply chain compromises, cross-repository data leaks, path traversal flaws, and authentication failures. The findings demonstrate that safeguarding agentic AI frameworks require multi-layered technical controls, zero-trust architecture, automated schema validation, and strict identity governance, rather than reliance on static boundary controls.