Lesson 18 / 25

Trusting Servers

Treat MCP servers as code you run and vet them like any dependency.

A server is code

A local MCP server is a program on your machine with your file and network access. A remote one may see everything you send it. Prefer official or well-reviewed servers, pin versions, read what a server does before installing, and avoid copy-pasting setup commands from unknown posts.

Every boundary is a risk

Servers run code, tool results enter the model's context, and the model can be steered by text. Each link needs a defence.

Four checkpoints: trust, scope, approve, log.
Figure 6.1 — Trust, scope, approve and log.

Beware tool descriptions that change

A server can change its tool descriptions after you approved it. Treat description text as untrusted input to the model, and re-review servers after updates.

Quick check: What is the safest attitude toward a third-party MCP server?

  • Install anything with many stars blindly
  • Treat it like any code dependency: review, pin and limit it
  • Run it as administrator for compatibility
  • Disable all logging
Answer

Treat it like any code dependency: review, pin and limit it — A server executes code with your permissions, so the usual supply-chain care applies.