Helixar-AI/mcp-security-checklist
View on GitHub ↗MCP is being adopted rapidly. Security guidance is lagging behind. This checklist gives security engineers, platform teams, and technical leaders a clear, actionable baseline for securing MCP deployments , whether you're shipping an internal tool or a customer-facing AI agent.
22 ★5 forksUpdated 6mo ago
What you need to know
A community-maintained security checklist for teams building and deploying MCP servers and AI agent infrastructure, covering authentication and authorization, input validation and prompt injection, tool and resource exposure, API session security, and monitoring.
Key features
- ✓Auth and authorization checklist
- ✓Input validation and prompt injection
- ✓Tool and resource exposure
- ✓API session security
- ✓Monitoring
Best for
Teams building and deploying MCP servers who need a security checklist.
Topics
agentic-aiai-agentsai-securitybest-practiceschecklistdevsecopshelixarllm-securitymcpmodel-context-protocolprompt-injectionsecuritysecurity-hardeningthreat-modeling
- Stars
- 22★
- Forks
- 5
- Language
- —
- License
- MIT
- Created
- 2026-03-09
- Last push
- 2026-03-09