Sponsored Content
AgentGuard

MCP Security for AI Agent Systems

Review MCP servers before trust, inspect documented trust and hook-layer controls, and keep third-party runtime calls outside complete coverage visible.

AgentGuard's public FAQ says it cannot fully monitor or block all third-party MCP server runtime calls.

Map MCP Runtime Risk

Server as a Trusted Component

A server, package, or tool implementation can introduce malicious or vulnerable behavior.

Tool Descriptions and Returned Content

An agent may receive instructions or context that influences later decisions.

Host Permissions

The MCP host determines which files, credentials, networks, and systems a tool can reach.

Runtime Tool Calls

Some third-party MCP runtime calls may remain outside the available observation or blocking path.

Review MCP Servers

Identify the Server

Record its source, package, owner, requested permissions, and update path.

Use a Documented Scan Surface

The public homepage includes MCP servers in Deep Scan coverage, and the API Reference lists an MCP-server scan endpoint.

Review the Result in Context

Inspect findings alongside provenance, configuration, dependencies, permissions, and material changes.

Evaluate Security Layers

Scans

MCP servers are named as Deep Scan targets, and an MCP-server scan endpoint is listed.

Scan depth, supported inputs, and output behavior.
Reputation and Trust Registry

The public FAQ names reputation and trust-registry signals as MCP risk-reduction layers.

Data sources, freshness, decision logic, and ownership.
Hook-Layer Controls

The public FAQ names hook-layer controls as another layer.

Which hosts expose the relevant calls and what outcome the hook can enforce.

Keep Runtime Gaps Visible

AgentGuard's public FAQ says it cannot fully monitor or block all third-party MCP server runtime calls. Coverage depends on the host, integration mode, and whether the relevant action reaches an observable control point.

Target MCP host
Server and tool path
Available hook
Actions in scope
Observed decision
Calls outside the path

Test Server, Host, and Runtime

Verify server provenance and ownership.
Review permissions and data access.
Scan before use and after material changes.
Record dependencies and update behavior.
Confirm the host integration mode.
Test expected tool-call decisions.
Inspect the evidence produced.
Document calls outside the control path.

Run an MCP POC

Step 1

Use Deep Scan and the API documentation to review the component surface.

Step 2

Use Runtime Guard only where the selected integration can evaluate the relevant action.

Step 3

Record observed decisions and calls that remain outside the control path.

Can AgentGuard scan an MCP server?
Yes. MCP servers are named as Deep Scan targets, and an MCP-server scan endpoint is documented.
Can AgentGuard monitor or block every third-party MCP runtime call?
No. The public FAQ explicitly states that current limitation.
How do reputation and trust-registry signals work?
The reviewed evidence does not establish the complete sources, freshness, or decision logic.
Which MCP hosts have verified coverage?
First-party materials list MCP hosts as an entry point, but protection depth must be verified for the target host.

Verify MCP Coverage

Define the users, decisions, evidence, and ownership required before choosing the implementation path.