AI MCP architecture network
– Anton Grabolle / Better Images of AI / CC BY 4.0

Released late last year by AI firm Anthropic, model context protocol (MCP) is an open standard designed to standardize the way AI systems, particularly large language models (LLMs), integrate and communicate with external data sources, tools, and systems.

MCP can assist developers to query data, run vector queries, generate reports, and perform data handling operations. And while not a networking protocol, it could also aid networking and security teams in handling downstream effects, mainly around traffic flow and governance.

LF Networking (LFN), for example, recently released a modular, open-source framework aimed at advancing the integration of AI into networking applications, supporting MCP. There's also Google’s Agent2Agent (A2A) protocol, which aims to establish industry-wide standards for AI agent interoperability.

On the security front, the Google Cloud Platform (GCP) has seen MCP capabilities integrated into its Security Command Center (SCC), while Cisco Data Fabric can now integrate with an MCP server. Cloudflare has also introduced an open beta to its zero trust platform. Here, MCP server portals provide a single wraparound URL through which every MCP server must pass before it can communicate with LLMs. This sees prompt traffic and tool calls logged in one location, potentially making it easier to audit who accessed which server and for what reason.

Dominic Wellington, AI and data expert at SnapLogic, sees increasing need for the standard as the low-key, unmanaged usage of AI apps in an organization rises, potentially leading to unsanctioned and shadowy data leaks.

“A familiar risk is ‘shadow AI’ adoption directly by end-users, bypassing corporate IT departments entirely,” explained Wellington. “This is why a ‘wait and see’ approach is quite unsustainable [with MCP]. It’s better to provide safe, sanctioned access than to block tools users are already finding value in, especially since any negative impacts on network architectures and operations may not be visible to those same end-users.”

In other words, AI sanctioned by MCP can help fight back against shadow AI. But MCP is in its early days, as Ian Quackenbos, head of the SUSE AI Innovation Hub, warned SDxCentral.

The AI expert sees MCP meaning less custom integration work and a path to automation that’s more modular for network teams.

“It’s still at the ‘concept’ stage for most clients, so they’ll need to be educated on what it is and why it matters,” he said. “Network teams need governance and guardrails so agents can’t take actions that disrupt production.”

MCP mistakes

Quackenbos and Wellington agree that if MCP lets autonomous AI agents take network actions, then safety guards will be needed to provide any accidental outages should the wrong action be taken by an agent.

Conor Sherman, CISO in Residence at Sysdig, recommended adapting zero trust and policy-as-code (PaC) frameworks that are already proven in cloud and DevOps. He recommended the Secure Production Identity Framework For Everyone (SPIFFE) specification and its implementation through the SPIFFE Runtime Environment (SPIRE) for strong workload identity, combined with Kubernetes policy and governance tool OPA (Open Policy Agent) Gatekeeper to enforce ingrained POC guardrails.

“Every MCP agent action should be issued a short-lived credential tied to its specific task, and OPA policies should require additional approval (human or automated) before high-impact commands touch production systems,” said Sherman. “This creates the ‘safety catch’ so agents can move fast on safe tasks, but anything risky hits a policy checkpoint that blocks, quarantines, or escalates before damage is done.”

“Human oversight is required for particularly risky actions, much like the two-person rule already used in strategic operations teams,” added Wellington.

Painful payloads

Away from agentic errors is the possibility of maliciousness via MCP usage, with recent Forrester research describing MCP as an emerging surface for exploitation; where Google's A2A protocol coordinates agents, MCP takes things further by implementing actions on behalf of users.

One tool derived from the Anthropic open standard, Mcp-remote, operates like a local proxy, enabling MCP clients to establish communication with remote MCP servers over the network, as opposed to operating them locally on the same host as the LLM application.

A remote code execution (RCE) vulnerability in the tool was discovered this year, allowing bad actors to launch arbitrary OS command execution on the host running Mcp-remote when it opens a connection to an untrusted MCP server.

A similar RCE flaw was discovered to affect MCP Inspector, a developer tool for testing and debugging MCP servers, which expose defined capabilities through the protocol, allowing AI systems to retrieve and work with information that extends beyond their original training data.

“In addition, Trend Micro discovered 492 and Knostic AI found over 1,800 MCP servers exposed to the internet, reminding security leaders of unsecured S3 buckets in Amazon Web Services (AWS) in the not-so-distant past,” Forrester wrote in its report.

Sysdig’s Sherman makes the analogy that just as next-generation firewalls let users spot malicious payloads in transit over a network through deep packet inspection, networking teams “now need to detect when the data itself is the malicious payload, hidden prompt injections, or poisoned instructions delivered through MCP.”

“The risk is that enterprises will rush to adopt MCP for its interoperability without realizing that, unlike A2A, the ‘payload’ itself can be weaponized, carrying poisoned instructions or enabling covert exfiltration,” he warned. “There is still a widespread need for community education around best practices and security controls.”

Sherman advises that zero trust is baked into agents from the start, and that security tools must correlate identity, task, and traffic at the connector level to ensure that the data being moved is safe and matches its intended purpose.

"AI agents are a new class of networked users: fast, privileged, and often invisible to legacy tools, with micro-segmentation to contain the blast radius of a compromised agent and identity-based access so that every agent is verified, scoped, and continuously checked."

Will MCP become a standard in tomorrow's networks?

SnapLogic’s Wellington agreed that MCP lacks some critical enterprise security requirements, with the protocol still being immature. But the AI expert isn't convinced it will see mainstream adopion, even after full development.

"Where working solutions without MCP already exist, introducing MCP would add overhead and complexity for no particular functionality gain.

"Secondly, even in cases with no existing integration, using MCP for large-scale integrations may not be cost-effective due to token cost overhead on each transaction. MCP is an interesting addition to the toolbox, but at least for now, it is not expected to supplant proven approaches."

Sherman though gives the CISO view that MCP will become the default agent interface in future networks, and the universal translator between AI tools and infrastructure.

"However, for an agent to make effective decisions, it requires more than just access – it needs the right context. That means awareness of the current state, the desired state, and the runtime environment in which it’s operating. Without that situational context, an agent will make low-quality recommendations or decisions and potentially impact production.

"Just as APIs standardized how apps communicate, MCP has the potential to standardize how AI agents integrate with corporate systems," he said.