The AI Learning Hub Journal

Model Context Protocol (MCP)

AI Host(Claude, IDE, app)contains MCP ClientJSON-RPC(stdio / HTTP)MCP Serverexposes capabilitiesToolsCallable functionsResourcesData, filesPromptsTemplatesModel Context ProtocolEvery MCP connection is a potential injection vector — auth and audit matter
MCP standardizes how AI hosts call tools — replaces N×M custom integrations with one protocol

The Problem MCP Solves

Before MCP, every AI app integrated with every tool through bespoke glue code — N×M integrations. MCP is an open standard (originally from Anthropic, now broadly adopted) that gives models a uniform way to discover and call tools, retrieve resources, and use prompts from external servers.

How It Works

An MCP server exposes capabilities — tools (callable functions), resources (data), prompts (templates). An MCP client (the AI host application) connects, negotiates, and calls them through a standardized JSON-RPC protocol. Auth, schemas, and discovery are all built in.

Why It Matters for Security

MCP is becoming the de facto integration fabric for agentic systems. Google SecOps, Gemini Enterprise, and most major platforms now expose MCP servers or consume them. This means your platform openness is increasingly measured by MCP support — and so is its attack surface.

The Security Angle

Every MCP connection is a potential injection vector. A malicious MCP server can poison context, exfiltrate data, or manipulate tool calls. Discovery questions to ask prospects: How do you authorize MCP servers? Do you scan tool definitions for injection? Where does the audit log live for agent-to-tool calls?

Prefer slides, quizzes, and saved progress? Read this lesson in the library — free, no sign-up.