What is an MCP
Security Proxy?
“MCP gives AI agents a hand. A security proxy determines whether that hand can be turned against you.”

The Problem: MCP Was Built for Capability, Not Defense
The Model Context Protocol (MCP) has become the dominant standard for connecting AI agents to external tools — filesystems, APIs, databases, and shell environments. By mid-2026, over 200,000 MCP server instances are estimated to be directly exposed to the internet, and security researchers have catalogued active CVEs with CVSS scores of 9.8 in production deployments.
The core architectural issue: MCP was designed for capability, not for defense. It exposes a rich surface of tool calls that an AI agent can invoke on the basis of text instructions alone. When those instructions can be manipulated — via prompt injection, poisoned retrieval context, or malicious MCP server responses — the consequences are not theoretical.
What an MCP Security Proxy Does
An MCP security proxy is an interception layer that sits between the AI agent and the MCP server. MCP tool calls routed through the proxy are inspected before they reach the upstream server. In enforce mode, BLOCK decisions prevent the routed call from reaching the upstream server; in monitor or audit mode, would-block decisions may be logged while traffic continues.
Real Attack Scenarios
Prompt Injection → Tool Hijacking
An attacker embeds adversarial instructions in a document the agent is summarizing. The instructions redirect the agent to invoke a file-deletion tool on critical system files. Without a proxy, the MCP server may execute the command. With an enforcing proxy, the routed tool call is evaluated against policy and can be blocked before execution.
Prompt Injection — ProvnAI Glossary
SSRF via Tool Parameters
An agent with a web-fetch tool is instructed to target an internal cloud metadata endpoint (169.254.169.254) to exfiltrate IAM credentials. A proxy with configured network destination rules can block common localhost, metadata-service, and private-address targets before the routed request reaches the upstream tool or server.
SSRF — ProvnAI Glossary
Path Traversal in Filesystem Tools
A file-read tool is called with ../../etc/passwd to read sensitive files outside the intended working directory. A proxy can normalize paths and enforce configured containment before the routed request reaches the filesystem server.
Path Traversal — ProvnAI Glossary
Metadata Poisoning
A compromised MCP server returns a poisoned tools/list response with hidden malicious tool definitions. The proxy can inspect configured suspicious metadata patterns before they reach the downstream model.
Tool-Call Hijacking — ProvnAI Glossary
A Five-Layer Defense Architecture
Effective MCP security cannot rely on a single control. The NIST AI Risk Management Framework recommends defense-in-depth for AI systems — multiple independent controls that each reduce risk independently but compound together.
Transport Isolation
MCP servers should never be directly reachable from the internet. Place them behind an authenticated proxy. Enforce mTLS between agent runtime and MCP server.
Deterministic Rule Enforcement
A rules engine at the proxy layer evaluates routed tool calls before execution. Allowlists for permitted tool names and schemas. Pattern matching for known attack signatures.
Semantic Intent Scoring
Rules catch known patterns. When enabled, semantic scoring can evaluate routed tool-call arguments against configured context and policy signals.
Behavioral Monitoring
Track tool call frequency, argument variance, and sequence patterns per session. Rate limits and behavioral anomaly detection catch exfiltration and misuse that rules miss.
Audit and Evidence
Baseline proxies emit structured audit events. Higher-assurance VEX-integrated deployments can preserve selected governed actions as tamper-evident evidence.
How McpVanguard Implements This
McpVanguard is an open-source MCP security proxy built around deterministic enforcement, with optional semantic and session-level controls. It can be introduced without changing existing MCP server implementations and works in both local stdio mode and hosted gateway mode.
Wrap any existing stdio MCP server with vanguard start --server "npx @modelcontextprotocol/server-filesystem ."
Expose hardened SSE and Streamable HTTP endpoints with authentication, JWT validation, and per-client policy enforcement.

Secure your MCP deployment today.
McpVanguard is an open-source security proxy for MCP designed for low-friction deployment in front of existing servers.
MCP Security in Production: The Definitive 2026 Guide
A layer-by-layer guide to securing MCP deployments — attack surface, five-layer defense, and production checklist.
Why MCP Security Needs Layered Runtime Enforcement
Why McpVanguard v2.1.0 treats semantic scoring as an advisor and formalizes five-layer runtime enforcement for MCP.
MCP Prompt Injection: Tool-Calling Vulnerabilities and Defenses
How direct and indirect prompt injection reaches MCP tool calls, and where deterministic defenses stop execution.
McpVanguard MCP Security Proxy
Open-source MCP security proxy for inspecting tool calls, enforcing policy, and blocking risky actions before execution.