MCP is basically web services for AI tools, thus the same care should be in place for security, unfortunely that isn't what happens, thus as usual DevSecOps will have lots of fun.
100%!! All AI tooling (MCPs, skills, models etc) has to go through the same scrutiny applied to any other web service. But as always, security is an afterthought that comes back to bite.