What Breaks When Agents Get Tools: MCP Security in Production
RAI Amsterdam · 17–18 September 2026 · Amine Raji, Molntek
The Model Context Protocol made it trivial to give an agent real tools, and just as trivial to hand an attacker a path to them. This talk walks the attack chain that keeps recurring in production MCP deployments: a poisoned tool description steers an agent into calling a privileged tool on an attacker's behalf, and nothing in the request looks anomalous. Then it walks the containment that actually holds, drawn from running agents with real credentials across multi-cluster Kubernetes estates.
Material from the talk
Slides and the demo go up here right after the session, and the full write-up follows a couple of weeks later. This page is the permanent home for both, so the link on the last slide keeps working.
Three things to do on Monday
If you take nothing else from the session, take these.
- 1
Inventory which MCP servers your developers have already connected, and to whose identity. Most teams find servers nobody registered.
- 2
Scope the agent's tool permissions to the task, not to the developer who built it. Confused-deputy attacks need privilege to be worth anything.
- 3
Put a human gate in front of the irreversible actions only. Gate everything and your team routes around it within a week.
Score your own agents, free
The Agent Security Scorecard asks the same questions I use in a paid review and gives you a gap list in the browser. No login, no email, nothing to install. It is the fastest way to find out whether what you just heard applies to you.
Open the Scorecard →If you want this run against your own system
That is what I do for a living. The two-day AI Security Sprint is €3,500 and answers one question properly: where the real exposure sits in the system you are least sure about. Prices for everything else are on the services page, and I would rather tell you on a call that you do not need me than sell you something you do not.