The risks specific to MCP, and the guardrails that hold
Lesson 1 of the module "The risks specific to MCP" in the course "Connect AI to your tools and data with MCP".
Lesson objective
By the end of this lesson, you will be able to recognize the seven risks specific to MCP (tool poisoning, rug pulls, injection through results, over-broad permissions, confused deputy, token passthrough, supply chain) and match each one with a structural guardrail and a detection signal.
Where it fits
The risks specific to MCP
What can an MCP server get wrong, and what stops it?
Lessons in this module
- The risks specific to MCP, and the guardrails that hold (this lesson)
What you will learn in the course
This lesson is part of the course Connect AI to your tools and data with MCP
- Explain what MCP standardizes (host, client, server; tools, resources, prompts; transports; authorization) and what each element implies for a product.
- Choose between an MCP server, a direct API integration, an in-house tool and a skill for a given need, and justify the choice.
- Find, evaluate and connect an existing MCP server in a free client, with limited rights, and verify what it actually exposes.
- Identify the risks specific to MCP (tool poisoning, rug pulls, injection through results, over-broad permissions, confused deputy, supply chain) and specify the matching guardrails.
- Decide whether to expose your product as an MCP server and, if so, specify its scope (users, tools, rights, authentication, measurement).
Related courses
- Build an AI assistant for your productAdvanced · ~3 hr
- Design a RAG architecture that fits your productAdvanced · ~3 hr 30 min
- Evaluate an AI feature: test sets, metrics and LLM judgesAdvanced · ~3 hr