Topic 1: Module 8 at a glance
MCP hands a language model a set of tools and lets it decide what to call. That is the whole point, and it is also the whole problem. In every earlier module we made the assistant more capable. This module is about the fact that capability cuts both ways: the same channel that lets a helpful server describe a search tool lets a hostile server describe a trap, and the model reads both the same way.
We will not hand-wave. Every attack in this module is run for real against small example servers, with a scripted stand-in "model" that follows instructions it reads, so you can watch the mechanism work. Then we turn on each defence and watch it stop.
By the end of this module, you'll have:
- A concrete threat model for MCP: why a model that reads tool descriptions and results adds attack surface that ordinary API security does not cover, drawn as a trust-boundary diagram.