MCP security interview: threat model for agent tools (EXPLAINED)

TL;DR — Quick Answer
Treat MCP servers as untrusted code execution surfaces. Defend with allowlists, sandboxes, signed configs, human approval for high-risk tools, input/output filtering, and full audit logs.
The Interview Question
Threat-model an MCP-based coding agent. Cover prompt injection, malicious MCP servers, .mcp.json supply-chain risks, and runtime governance controls.
Deep Explanation
Sign in to unlock full answer
Get deep explanations, PDF export & all MCP questions
- 4 more sections of deep explanation
- Real-world examples
- Common mistakes
- Interviewer expectations
- Follow-up questions
MCPSecurityPrompt InjectionGovernanceAnthropicMicrosoftGoogle