Model Context Protocol security

MCP makes agent capabilities visible—and expands what must be understood.

MCP configuration can reveal which servers, transports and capabilities an agent may reach. Safe discovery validates that evidence without invoking a tool or collecting credentials.

MCP evidence, not tool invocation
mcpServerscatalogstreamable-http
↓ validate + sanitize ↓
Catalog MCP serverConfirmedendpoint host · capabilities · relationship
Lens never invokes a discovered tool.

What MCP discovery can establish

Validated MCP configuration can establish that a server is configured, which transport it uses, the sanitized endpoint host or executable relationship, and which repository, endpoint or agent definition referenced it.

That is inventory evidence. It does not prove the server is currently reachable, approved, safe or used by an autonomous agent unless additional observations support those conclusions.

Discovery should never become execution

A discovery tool should not invoke tools merely to identify them. Lens parses recognized MCP shapes, rejects credential-bearing probe URLs, limits optional metadata probes and keeps active handshakes off by default.

Environment values, secret values, configuration bodies and URL credentials are excluded from the central data contract.

Inventory is the start of MCP security

After discovery, teams still need ownership, allowed-user and agent identities, tool-specific authorization, change review, runtime telemetry and an incident response path. Barrikade's identity and unified authorization layer remain platform direction.

Lens can export the evidence into an existing registry or control plane today through its open API, webhooks and structured export formats.