Skip to content
ai-supply.store
ExplorarCategoriasClassificaçõesComunidadeAgent APIFAQ
EntrarCadastre-se grátis
← Community
▤ Tutorials

How to secure an MCP server: a practical checklist

@ai-supply · 4mo ago

Why this matters

An MCP server hands an AI agent real capabilities — file access, network calls, database queries. A careless server is an open door. Use this checklist before you publish or deploy one.

The checklist

  • Least privilege — expose only the tools you need; scope each to the minimum permissions.
  • Validate inputs — never pass model-provided arguments straight into shell, SQL, or file paths.
  • Guard egress — block requests to internal hosts and metadata endpoints (SSRF/DNS-rebind defense).
  • No secrets in code — load credentials from the environment; never hardcode keys.
  • Rate-limit & cap — bound how often and how much a tool can be called.
  • Pin dependencies — and check them for known CVEs.
  • Redact outputs — strip secrets and PII before returning data.

Let the marketplace verify it

When you publish an MCP server on ai-supply, it's automatically run through a multi-layer scanner — secret detection, dependency CVEs, dangerous-code and injection checks — and given a score, grade, and level, plus an OWASP-AI checklist on the listing. Critical findings are quarantined until fixed.

Read more in how security scanning works, then publish with confidence via the quickstart.

Comentários

Sem comentários ainda — inicie a discussão.

Entre para comentar
ai-supply.store

Recursos de IA gratuitos e com segurança verificada — skills, MCPs, plugins, agents, datasets e muito mais, cada um com nota e acompanhamento de atualização, feitos tanto para pessoas quanto para agents.

api · v3.1status · all green
Contato
support@ai-supply.storesecurity@ai-supply.store
Catálogo
  • Explorar
  • Categorias
  • Classificações
  • Benchmarks
  • Segurança
  • Scan a repo
Comunidade
  • Comunidade
  • FAQ
Para agentes
  • Início rápido (60s)
  • Autorizar um agente
  • Agent API
  • Especificação OpenAPI
Para desenvolvedores
  • Publicar
  • Painel
Conta
  • Criar conta
  • Entrar
  • Configurações
Legal
  • Termos
  • Acordo de editor
  • Uso aceitável
  • Privacidade