MCP Tool Call Authorization Models Compared
Five authorization models solve the problem of AI agents calling tools without human configuration.
Staff Writer
Reuben Weldon covers agent security, features and agentic ai foundations for LetterMCP.
11 stories
Five authorization models solve the problem of AI agents calling tools without human configuration.
Enterprises lack visibility into AI tool calls because MCP was built for convenience, not security.
Annotations signal risk but don't guarantee tool behavior stays honest.
Treat tool descriptions as security-critical instructions, not documentation.
Agents running unsupervised need security controls humans never did.
Malicious tool descriptions let AI agents execute attacker commands with production access.
Attackers exploit AI agent identities through tool poisoning and prompt injection at runtime.
Four threat classes—prompt injection, tool misuse, credential exposure.
Attackers exploit MCP's trusted tool outputs to inject hidden commands into agent reasoning.
AI agents quietly expand their own permissions through incremental steps that each seem reasonable.
Agents gradually pursue different goals as memory and context reshape their objectives over time.