Model Context Protocol (MCP) is Anthropic's open standard for connecting AI models to external tools and data sources. In 2026, MCP is the primary integration pattern for Claude Desktop, a rapidly growing number of enterprise AI deployments, and almost every serious AI agent framework. It is also one of the most under-secured attack surfaces in production AI systems.
When an AI model makes a tool call via MCP, it is executing code on your infrastructure based on instructions that came — in whole or in part — from model output. If that output can be influenced by user input (and it almost always can), you have a prompt injection vector that can reach your databases, file systems, and external APIs.
The MCP Attack Surface
There are four main attack vectors against MCP-connected systems:
- 1.Direct prompt injection — a user crafts input that instructs the model to call a tool it should not, with arguments it should not use
- 2.Indirect injection via tool output — data returned by a tool contains embedded instructions that the model follows in subsequent turns
- 3.Tool scope escalation — the model is convinced to use a tool outside its intended scope (read-only tool used to write)
- 4.Replay attacks — a tool call is recorded and replayed outside the session context
Putting a Boundary Around a Tool Call
A boundary around a tool call limits what the call can do, independent of what the model wants to do. The model is not trusted to self-limit. In G8KEPR the boundary has two parts: checks the proxy runs on every tools/call before forwarding it (backend/modules/mcp/interceptor.py), and OS-level limits on the stdio MCP servers the proxy launches (backend/modules/mcp/interceptor_transport.py).
Scope enforcement
Every tools/call is checked against the tool permission store, the approval workflow for tools that need one, and the tool call graph and annotation policy. A call that fails any of these is blocked — not rerouted, blocked — and the attempt is logged.
Parameter validation
Tool arguments are scanned by the threat detectors before the call is forwarded, and a detected threat can block the call. Arguments are also checked against the input schema the tool declared, but today a schema mismatch is only logged as a warning; it does not block the call.
Rate limiting per tool
Bulk data exfiltration via tool calls is a real attack pattern. An agent that makes 500 read_file calls in 60 seconds is doing something wrong. Each tool is rate limited per user (60 calls a minute by default, backend/modules/mcp/rate_limiter.py), which caps the blast radius of a compromised session.
Process limits on launched servers
When the proxy launches a stdio MCP server (off unless the operator sets MCP_STDIO_SERVERS_ENABLED), the command must start with an allowlisted interpreter or package runner, runs with no shell and with inline-code flags rejected, and gets a scrubbed environment. That is input hygiene, not a code-execution boundary: whoever registers a server chooses what runs. On Linux the process then gets setsid(), RLIMIT_NPROC/NOFILE/AS/FSIZE ceilings (the launch aborts if one cannot be set), a best-effort no-new-privileges and ambient-capability clear, and a drop to nobody if started as root. There is no RLIMIT_CPU and no seccomp filter, and network egress is not filtered: a server that exists to call an external API needs the network, so egress control belongs at the host or network layer.
Audit Trails
Every tool call that passes through G8KEPR generates an audit log entry with: session ID, model version, tool name, parameters (redacted for sensitive fields), response hash, timestamp, and whether the call was allowed or blocked. The log table is append-only: a database trigger blocks deletes and edits to core fields. Authentication and domain events are also HMAC-SHA256 hash-chained per tenant and verified daily (since 2026-09-13); tool-call rows are outside that chain.
This matters for compliance: EU AI Act Article 12 requires that automated decision systems maintain logs enabling post-hoc review. If your AI agent takes an action via MCP that turns out to be incorrect or harmful, you need to be able to reconstruct exactly what happened.
Where It Sits
The G8KEPR MCP proxy slots in between your AI framework and your MCP servers — no changes to your model code or your tool implementations.
