A server, package, or tool implementation can introduce malicious or vulnerable behavior.
MCP Security for AI Agent Systems
Review MCP servers before trust, inspect documented trust and hook-layer controls, and keep third-party runtime calls outside complete coverage visible.
AgentGuard's public FAQ says it cannot fully monitor or block all third-party MCP server runtime calls.
Map MCP Runtime Risk
An agent may receive instructions or context that influences later decisions.
The MCP host determines which files, credentials, networks, and systems a tool can reach.
Some third-party MCP runtime calls may remain outside the available observation or blocking path.
Review MCP Servers
Record its source, package, owner, requested permissions, and update path.
The public homepage includes MCP servers in Deep Scan coverage, and the API Reference lists an MCP-server scan endpoint.
Inspect findings alongside provenance, configuration, dependencies, permissions, and material changes.
Evaluate Security Layers
MCP servers are named as Deep Scan targets, and an MCP-server scan endpoint is listed.
Scan depth, supported inputs, and output behavior.The public FAQ names reputation and trust-registry signals as MCP risk-reduction layers.
Data sources, freshness, decision logic, and ownership.The public FAQ names hook-layer controls as another layer.
Which hosts expose the relevant calls and what outcome the hook can enforce.Keep Runtime Gaps Visible
AgentGuard's public FAQ says it cannot fully monitor or block all third-party MCP server runtime calls. Coverage depends on the host, integration mode, and whether the relevant action reaches an observable control point.
Test Server, Host, and Runtime
Run an MCP POC
Use Deep Scan and the API documentation to review the component surface.
Use Runtime Guard only where the selected integration can evaluate the relevant action.
Record observed decisions and calls that remain outside the control path.
Can AgentGuard scan an MCP server?
Can AgentGuard monitor or block every third-party MCP runtime call?
How do reputation and trust-registry signals work?
Which MCP hosts have verified coverage?
Verify MCP Coverage
Define the users, decisions, evidence, and ownership required before choosing the implementation path.