Home/FAQ

Can MCP Servers Steal My Info

The real risks of MCP servers: data access, credential handling, and exfiltration paths.

Answer

Yes, if you grant a server access to sensitive data or credentials, it can exfiltrate data like any integration. The risk is controlled by permissions, isolation, and auditing at the server/gateway layer. Use least privilege and only enable tools you trust.

Nuances & Considerations

The biggest risk is overbroad permissions ("read everything" or "write anywhere"); start default-deny and expand slowly.

Related