Connecting
Learn/L13 · Model Context Protocol (MCP)

Security risks

An MCP server can read or change real systems. Treat with extension-level paranoia.

Difficulty 2/5
Short

Plain English

An MCP server can read or change real systems. Treat with extension-level paranoia. Picture it like this: A USB drive of unknown origin. In the apps you ship (Agentify, wedding portals, CRM), you will bump into this on almost every screen — name it clearly when you prompt your coding agent.

Analogy

A USB drive of unknown origin.

Go deeper

An MCP server can read or change real systems. Treat with extension-level paranoia.

Common mistakes

  • Letting the AI rename this concept three different ways in one PR.
  • Building UI before you can say what is stored and who can change it.

AI-agent trap

Agents may invent jargon here. Ask them to explain the concept in plain English first, then map it to your schema and one real screen.

Summary

An MCP server can read or change real systems. Treat with extension-level paranoia. A USB drive of unknown origin. Ask yourself: where does this live in the database, which function changes it, and which screen shows it?

Confidence: