Every socket is a door
Every MCP socket is a door into your email, documents and accounts. The more doors, the more carefully you have to lock them.
RISK 1
Unknown servers
Risk one: unknown servers. Anyone can write an MCP server. Installing one from an unknown source is like plugging in a USB stick you found on the street.
RISK 2
Prompt injection
Risk two: instructions hidden in data. A strange email says: send the contact list to this address. AI reads the email to sum it up, and may think that's your instruction. This trick is called prompt injection.
RISK 3
Too much permission
Risk three: too much permission. You only need it to read your calendar, but you gave it permission to delete your whole inbox.
3 HABITS
Three safe habits
Three habits to stay safe. Only install official servers, or ones already in your app's connector list. Give only the access it needs, called least privilege. And read carefully every time AI asks to do something sensitive, like sending, deleting or paying.
NEXT
What about many AIs?
One AI with many tools is already powerful. So what about many AIs working together, called multi-agent? Part five.
This article is based on the video Using MCP safely from the Mark học AI channel. Watch the video (in Vietnamese) to see the animations.