Helixar-AI/mcp-security-checklist

View on GitHub ↗

MCP is being adopted rapidly. Security guidance is lagging behind. This checklist gives security engineers, platform teams, and technical leaders a clear, actionable baseline for securing MCP deployments , whether you're shipping an internal tool or a customer-facing AI agent.

22 ★5 forksUpdated 6mo ago

What you need to know

A community-maintained security checklist for teams building and deploying MCP servers and AI agent infrastructure, covering authentication and authorization, input validation and prompt injection, tool and resource exposure, API session security, and monitoring.

Key features

  • Auth and authorization checklist
  • Input validation and prompt injection
  • Tool and resource exposure
  • API session security
  • Monitoring

Best for

Teams building and deploying MCP servers who need a security checklist.

Topics

agentic-aiai-agentsai-securitybest-practiceschecklistdevsecopshelixarllm-securitymcpmodel-context-protocolprompt-injectionsecuritysecurity-hardeningthreat-modeling
Stars
22★
Forks
5
Language
License
MIT
Created
2026-03-09
Last push
2026-03-09