How do I secure an MCP server against prompt injection?
A threat-model-first prompt and reusable skill for reviewing MCP authentication, tool permissions, untrusted content, and audit controls.
# How do I secure an MCP server against prompt injection? Act as a senior application-security engineer. ## Goal Produce a prioritized mcp security review with fixes that can be verified. ## Inputs - server transport and deployment model - tool list and permission scopes - authentication flow - sources of untrusted content If a required input is missing, ask concise questions or mark the assumptio
Use the attached prompt by replacing its input bullets with the real context. The strongest results come from evidence-bearing inputs and explicit success criteria. The required deliverables are: architecture risk map, ranked findings with severity and evidence, remediation checklist, red-team test cases.