MCP Security

A policy gate in front of every MCP tool call.

MCP connects agents to email, databases, file stores and internal APIs. That is what makes it useful, and why an unapproved server or an over-powered tool becomes a route for data loss. InferenceFort checks each tool call before it leaves your process.

Where MCP goes wrong

Unapproved servers

Data goes somewhere nobody reviewed

A developer adds a community MCP server. Every call now sends arguments, which can include customer data, to a host your security team has never seen.

Over-powered tools

A tool that exists will get called

delete_*, send_email, run_query. Sooner or later an agent calls them, sometimes because an injected instruction asked it to.

Poisoned results

Tool output is untrusted input

A web page, ticket or document returned by a tool can carry instructions for the agent's next step.

Invisible activity

No record of who called what

Without a tool-level audit trail you cannot answer which agent called which server, with what arguments, and what came back.

The controls

Approve servers

List the MCP servers agents may call: exact hosts, subdomain wildcards such as *.internal.example.com, or local addresses. Matching is anchored to the host, so lookalikes such as tools.example.com.attacker.net do not pass. Calls to anything else are blocked before transport. Local stdio servers count as local.

Control tools

Block tools with patterns such as delete_* or *email*. Mark sensitive tools as approval-required: the call stops, and your application runs the human review and the authorised retry.

Screen arguments and results

Content rules and detectors run on tool arguments before the call and on returned text after it. A secret in an argument or an injection in a result is caught at the tool boundary.

Stop injection-to-exfiltration

Tools are classified as reading private data, bringing in untrusted content, or able to send data out, using your patterns or built-in heuristics. A call to an unapproved server also counts as untrusted. Once a session holds private data and untrusted content, the next tool that can send data out is blocked, or flagged if you prefer.

policy.json · fragment
{
  "mcp_servers": ["https://tools.internal.example.com", "*.mcp.example.com"],
  "mcp_policy": {
    "blocked_tools": ["delete_*", "drop_*"],
    "approval_tools": ["send_email", "transfer_*"]
  }
}

A complete record of every tool call

Each tool call produces two linked audit events that share one call ID. The first records the arguments and the decision. The second records the returned text. The MCP server is recorded as the destination, so every question about tool activity has an answer.

Trace context across MCP, without code

When an MCP client calls a server that is itself an instrumented agent, InferenceFort carries trace context in the request's reserved _meta field and continues it on the server. The downstream agent's calls join the same trace. Customer identity is never taken from the wire: the server uses its own, so a forged value cannot join another tenant's session.

Coverage

LanguageMCP and tool surfaces
PythonMCP ClientSession.call_tool, MCP server trace continuation, LangChain tools, CrewAI tools (direct and agent-loop calls)
TypeScript / NodeMCP client and server via the register hook, or wrapMcpClient / wrapMcpServer for ESM apps

Custom tool loops that bypass these surfaces are not governed automatically. Verify each path with a deliberate blocked call.

Frequently asked questions

Does it work with local stdio MCP servers?

Yes. Stdio and in-process servers are treated as local for the server allow-list, and tool policy, screening and audit still apply.

Can I require a human to approve a tool call?

Yes. Add the tool to approval_tools. The call is stopped with an approval-required verdict, and your application collects approval and retries.

Does it inspect tool descriptions for poisoning?

InferenceFort governs tool calls, their arguments and their results. Screening of tool descriptions is not a listed control today, so review third-party servers before approving them.

Does this replace MCP server authentication?

No. Trace continuation and policy do not authenticate callers. Keep your server's own authentication and authorisation.

Keep reading

Review your MCP integrations

Bring one agent workflow, the data it touches, and the actions you need to control. As a design partner, you shape the evaluation and review the policy decisions with our engineers.

Become a design partner →