MCP servers are quietly becoming your biggest agentic attack surface

Mukhtiar-Colazo30 · reddit · 2026-09-24

MCP makes handing tools to agents trivially easy — and that's the problem. Most real-world setups scope nothing: agents can call any tool against any host, and whoever wired it up never audited the tool list. Every MCP server is its own trust boundary; prompt injection is the entry point, but the tools (file reads, HTTP, repo writes) are what do the damage.

Original post →

More from coding & agent

coding & agent channel →