The public scanners said the MCP server was clean. Our audit found what they were structurally unable to see.
Model Context Protocol is becoming the wiring between AI agents and the tools, data, and systems they act on. The scanners built to vet that wiring look for known-bad patterns. We built a methodology to look for the class of exposure they were never designed to catch — and we found it.
Teams are wiring agents to production with a protocol most of their tooling can't reason about.
MCP standardizes how an AI agent reaches tools, files, and APIs. Adoption outran assurance: teams reached for whatever public scanner promised to "check" an MCP server, saw a green result, and shipped. A clean scan became a substitute for a security judgment.
A green scan is an answer to the wrong question.
Public scanners match patterns they already know.
Signature and heuristic checks flag the exposures someone has already catalogued. A new protocol produces new failure modes that no catalogue contains yet.
MCP assumes the tools it connects are behaving.
The protocol optimizes for capability and composition. Trust boundaries between the agent, the server, and the data it reaches are left to the implementer — and often to no one.
A passing scan is treated as a security decision.
The scanner answers "does this match anything I recognize?" Teams read it as "is this safe to run against production?" Those are not the same question.
We audited the protocol's trust model, not its signature surface.
Map the trust boundaries
Diagram every hand-off between agent, MCP server, and the resources behind it — and where authority is assumed rather than checked.
Model abuse, not malware
Ask what a compliant, "clean" server can be made to do by design — the failure a signature scan cannot express.
Reproduce it cold
Confirm the finding on a fresh environment so it stands as a repeatable method, not an anecdote.
Disclose responsibly
Document the exposure and remediation path before any public detail — certainty, engineered, includes restraint.
A finding the tooling market couldn't produce — and a repeatable way to produce more.
If your MCP security depends on a public scanner returning green, you are trusting a tool to answer a question it was never built to ask.
Find out what your MCP scan is missing.
Three ways to go deeper, matched to how ready you are to move.
MCP Audit Checklist
The trust-boundary questions a signature scan never asks. One-page download, no call required.
Download the checklist →Architecture review
We map your agent-to-tool trust boundaries with your team in a working session.
Book a review →Scoped MCP assessment
The full methodology run against your deployment, with a remediation plan you can act on.
Scope an assessment →