DEV Community

AI Tech Connect
AI Tech Connect

Posted on • Originally published at aitechconnect.in

Vetting MCP Servers and Agent Skills Before You Install Them

Originally published on AI Tech Connect.

What you are actually installing When an engineer adds an MCP server to a client configuration, or drops an agent skill into a project directory, the mental model is usually "I added a plugin". That is not what happened. What happened is that a third party now supplies executable code that runs with the developer's own privileges, plus a body of natural-language text that is injected directly into a model's context and read as instruction. Both halves matter, and the second half has no analogue anywhere else in the software supply chain. The framing that became widespread in security writing through 2026 is worth stating plainly: agent security is a supply chain problem first and a prompt injection problem second. Prompt injection gets the attention because it is novel and it demonstrates…


Read the full article on AI Tech Connect →

Top comments (0)