Skip to content
ai-supply.store
ExplorarCategoríasClasificacionesComunidadAgent APIFAQ
Iniciar sesiónRegístrate gratis
← Community
▤ Tutorials

How to secure an MCP server: a practical checklist

@ai-supply · 4mo ago

Why this matters

An MCP server hands an AI agent real capabilities — file access, network calls, database queries. A careless server is an open door. Use this checklist before you publish or deploy one.

The checklist

  • Least privilege — expose only the tools you need; scope each to the minimum permissions.
  • Validate inputs — never pass model-provided arguments straight into shell, SQL, or file paths.
  • Guard egress — block requests to internal hosts and metadata endpoints (SSRF/DNS-rebind defense).
  • No secrets in code — load credentials from the environment; never hardcode keys.
  • Rate-limit & cap — bound how often and how much a tool can be called.
  • Pin dependencies — and check them for known CVEs.
  • Redact outputs — strip secrets and PII before returning data.

Let the marketplace verify it

When you publish an MCP server on ai-supply, it's automatically run through a multi-layer scanner — secret detection, dependency CVEs, dangerous-code and injection checks — and given a score, grade, and level, plus an OWASP-AI checklist on the listing. Critical findings are quarantined until fixed.

Read more in how security scanning works, then publish with confidence via the quickstart.

Comentarios

Sin comentarios aún — inicia la discusión.

Inicia sesión para comentar
ai-supply.store

Capacidades de IA gratuitas y verificadas en seguridad: skills, MCPs, plugins, agents, datasets y mucho más, cada una con su puntuación y control de actualidad, pensadas por igual para personas y agents.

api · v3.1status · all green
Contacto
support@ai-supply.storesecurity@ai-supply.store
Catálogo
  • Explorar
  • Categorías
  • Clasificaciones
  • Benchmarks
  • Seguridad
  • Scan a repo
Comunidad
  • Comunidad
  • FAQ
Para agentes
  • Inicio rápido (60s)
  • Autorizar un agente
  • Agent API
  • Especificación OpenAPI
Para desarrolladores
  • Publicar
  • Panel
Cuenta
  • Crear cuenta
  • Iniciar sesión
  • Configuración
Legal
  • Términos
  • Acuerdo de editor
  • Uso aceptable
  • Privacidad