Source record · tier 1 standards and regulators
Model Context Protocol specification 2026-07-28, Security Best Practices
- Publisher
- Model Context Protocol project
- URL
- https://modelcontextprotocol.io/specification/2026-07-28/basic/security_best_practices
- Published
- 2026-07-28
- Updated
- unknown
- Accessed
- 2026-09-05
- HTTP status
- 200
- License
- MIT license; permitted under the specification license
Claims citing this source
- The 5 message flow diagrams on the Model Context Protocol security best practices page depict consent phishing a skipped consent cookie server side request forgery to a cloud metadata endpoint and script injection leading to arbitrary command execution and none of them concerns tool schemas. fact in context
- The Model Context Protocol security best practices page carries no section on tool schema change tool poisoning or rug pull attacks and its attack sections are all authorization shaped. fact in context
Cite this source record
APA
WarmTransfer. (2026, July 28). Model Context Protocol specification 2026-07-28, Security Best Practices. WarmTransfer. https://warmtransfer.net/knowledge/sources/mcp-spec-2026-07-28-security-best-practices
BibTeX
@misc{warmtransfer-mcp-spec-2026-07-28-security-best-practices,
title = {Model Context Protocol specification 2026-07-28, Security Best Practices},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/mcp-spec-2026-07-28-security-best-practices},
note = {Model Context Protocol project, accessed 2026-09-05}
}