How to Secure an MCP Server and Stop Secret Exfiltration
TL;DR
* A malicious or compromised MCP server's primary attack is secret exfiltration: it reads the tokens and API keys your agent holds and sends them to an external endpoint. The OWASP MCP Top 10 ranks token mismanagement and secret exposure as the largest risk in the Model