
In this fourth installment of SentinelOne’s Prompt Security series, we’ll take a closer look at the security of AI agents and the MCP protocol—a new front in today’s AI security landscape.
In my previous articles in Sentinel One’s Prompt Security series, which covered threat areas for employees, developers, and in-house AI applications, I will now turn to the most dynamic area of risk: AI agents and the Model Context Protocol (MCP).
MCP solved one problem and created another
The Context Protocol provided AI agents with a standardized way to connect to enterprise systems such as GitHub, Slack, Jira, databases, and the cloud. This ecosystem-based solution accelerated the adoption of Agentic AI, but security in the broadest sense clearly failed to keep pace with the speed of deployment.
The scale of the problem, as documented in 2026 by security researchers, is hard to ignore:
⬩ More than 10,000 publicly accessible MCP servers were analyzed, with the percentage of servers lacking any authentication reaching nearly 25%
⬩ Hundreds of servers are available on the Internet without traffic encryption or access controls, making them an easy target
⬩ The catalog of known MCP vulnerabilities, maintained by researchers affiliated with SentinelOne, Snyk, Trail of Bits, and CyberArk, among others, now includes several dozen entries, some of which are classified as critical
⬩ Only a small percentage of organizations have a formalized strategy for managing the identities of AI agents, and even fewer agents make it into production with full security approval.
Why do agents pose a different kind of risk?
Unlike a traditional application, an AI agent can perform actions on its own—launch tools, modify files, and connect to APIs. If it is granted broader permissions than it actually needs for the task, it becomes a potential backdoor into the systems it connects to. All it takes is a single command injected into the content the agent is processing to take control of its operations without cracking any passwords.
Prompt Security Response – MCP Gateway
This crucial pillar of the platform is, according to SentinelOne, the first comprehensive Agentic AI security solution, based on three mechanisms:
- Endpoint enforcement—via a lightweight agent or a reverse proxy for in-house applications, which allows you to control agent traffic regardless of where they are actually running
- MCP Dynamic Risk Assessment – continuous analysis of over 13,000 MCP servers available on GitHub, allowing organizations to assess what their agents are actually connecting to
- In-depth interaction monitoring—a complete, searchable log of every interaction between users, agents, and MCP servers, useful for both ongoing monitoring and post-incident audits.
Transparency Instead of Taking Someone at Their Word
A key shift in thinking in this area is that MCP servers should not be considered trusted by default simply because they operate within the organization. MCP Gateway allows you to detect unauthorized deployments of agents and servers before they become a vector for data leaks or system compromise.
What's next?
In the final part of this series, I’ll bring together all four areas covered in my previous articles into a single overview of the platform and explain why it’s worth viewing Prompt Security as a single, modular solution rather than a collection of standalone tools.
Are you already implementing AI agents in your organization? Contact ISCG—we’ll help you assess your current exposure to MCP risk.
Schedule a demo: https://outlook.office.com/book/KonsultacjaPromptSecurity@ISCG.onmicrosoft.com/s/Lc5jNKTyHUSx5as_9eqXOw2?ismsaljsauthenabled


