- Tool Poisoning: Malicious content in tool metadata can compromise LLMs, including “rug pull” attacks where descriptions are changed post-approval.
- Authentication Gaps: Many open-source MCP servers lack robust OAuth protection. Always verify your server’s security.
- Token Costs: MCP schemas can eat into your context window, inflating LLM API costs by 15–25% and, in severe cases, consuming over 70% of your available tokens.