NSA MCP Security Guidance: AI Agent Access to Firm Knowledge Requires Active Governance Architecture
BY INSIDE PRACTICE · AUGUST 10, 2026 · 1 MIN READ
NSA cybersecurity guidance published in 2025 on Model Context Protocol and agentic AI systems — receiving renewed attention this week as MCP deployments proliferate in legal — identifies five specific risk categories for enterprises deploying MCP: tool poisoning (malicious or manipulated tool definitions altering agent behaviour); confused deputy attacks (agents acting on behalf of a user but exceeding their intended permissions); rug-pull attacks (server-side MCP definitions changed after approval to introduce malicious instructions); shadow access paths (MCP connections bypassing DLP, audit logging, or ethical wall controls); and prompt injection through retrieved documents (malicious content in retrieved files that redirects agent behaviour). The NSA recommends: human approval gates for sensitive MCP server connections; allowlisting of approved MCP servers at the network and endpoint level; per-connection permission scoping rather than broad read access; audit logging of all MCP tool calls; and regular review of connected tool definitions for changes. For KM directors overseeing DMS deployments with MCP-connected AI agents, this guidance converts abstract security language into specific architecture requirements — and makes KM governance a live security risk management conversation rather than a policy document.