Standards are great. But do we really must keep on standardizing terrible security choices? MCP is transforming any AI assistant into an agent wielding powerful tools. Change a couple configurations, pop-in your API key, and you’re ready to go. But simplicity comes at a cost. MCP brings the full spectrum of supply chain risk into the AI world: untrusted code running locally, reliance on obscure cloud services, no modern authentication, hard-coded credentials. Worst of all, MCP servers can hijack the agents using them – remotely injecting malicious instructions and quietly redirecting the assistant’s behavior. We will introduce a totally-not-malicious MCP that allows AIs to connect to knowledge platforms like Confluence/Notion/ClickUp, for free! We’ll demonstrate how adding our server to Cursor, Windsurf and GitHub Copilot results in stolen credentials and source code. Or full data exfiltration of everything going through your agent in other cases. Even showing how the compromise can escape the agent’s scope entirely, leading to malware infections. Finally, we will present a threat model for MCP servers. You’ll come out of the session knowing how to analyze and approve secure MCP servers. And continue to monitor them to detect any future compromise or malicious behavior.