Hacker News new | ask | show | jobs
by evacchi 439 days ago
we also recently published our approach on MCP security for mcp.run. Our "servlets" run in a sandboxed environment; this should mitigate a lot of the concerns that have been recently raised.

https://docs.mcp.run/blog/2025/04/07/mcp-run-security

2 comments

The main concern I have is that there's not a well defined security context in any agentic system. They are assumed to be "good" but that's not good enough.
Good article, Edoardo! The ideas about securing MCP frameworks with servlets are really interesting. Just added your article to https://github.com/Puliczek/awesome-mcp-security