Security — Advanced
How do we handle third-party MCP servers safely?
Treat every MCP server as an untrusted extension. Vet the code (open-source is preferable), scope permissions narrowly (only the tools the workflow needs), monitor guardrail-trigger events, and require human confirmation for high-consequence actions the server triggers. Public MCP directories will eventually be attacked; assume it.
More on Security — Advanced
Browse the full FAQ for 164 answers, or start a free GenAI maturity assessment to see where your organisation stands.