Control
Agent tool servers or agent peers not authenticated
Every MCP, A2A, or tool-server endpoint authenticates its callers, including local development proxies, and every agent connects to remote servers over TLS to a configured, expected server identity.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Reach
The guard to add
Require a verified token on every MCP or tool-server endpoint, and connect agents to remote servers only over HTTPS with credentials to a fixed, configured URL.
Server side: every MCP, A2A, or tool server validates a bearer token before any tool runs (FastMCP token_verifier= with auth=AuthSettings(...), or an auth middleware in front of the endpoint), and binds to 127.0.0.1 rather than 0.0.0.0 unless authentication is configured; local development proxies follow the same rule. Client side: each remote server entry in .mcp.json or agent config, and each streamablehttp_client / StreamableHTTPClientTransport call, uses an https:// URL fixed in configuration (never taken from model output or retrieved content) and sends credentials via an Authorization header or OAuth.
Where it goes: 1 application source code, 3 config and feature flags, 6 API calls and integrations, 15 agent action surface.
What reviewers look for: no FastMCP(...) or mcp.run(...) bound to 0.0.0.0 without auth= or token_verifier=; MCP client configs and client code using https:// for non-localhost servers with headers.Authorization, oauth, or auth settings present; server URLs coming from config, not from the conversation.
Example (MCP Python SDK (FastMCP)), before:
mcp = FastMCP('files', host='0.0.0.0')
mcp.run(transport='streamable-http')After:
from mcp.server.auth.settings import AuthSettings
from pydantic import AnyHttpUrl
# JwtVerifier: our TokenVerifier subclass that checks signature, audience, and expiry
mcp = FastMCP('files', host='0.0.0.0', token_verifier=JwtVerifier(JWKS_URL),
auth=AuthSettings(issuer_url=AnyHttpUrl('https://auth.example.com'),
resource_server_url=AnyHttpUrl('https://files.example.com/mcp'),
required_scopes=['files:read']))
mcp.run(transport='streamable-http')Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Every rule this guard addresses
TwinEthos recommendation (not law) (1)
- Everywhere (*)
- Authenticate every agent tool server and verify every server an agent connects to TwinEthos derivation — guardrail.agent-tool-server-authentication
Related incidents
- Internet-exposed MCP servers without authentication (2025-07; confirmed). Trend Micro research found hundreds of Model Context Protocol servers reachable from the internet with no authentication (492 in July 2025; 1,467 in an April 2026 update). Source: Trend Micro research (researcher publication) · evidence grade: primary · cited by Authenticate every agent tool server and verify every server an agent connects to
- MCP Inspector proxy accepted unauthenticated requests to launch MCP commands (CVE-2025-49596) (2025-06-13; disclosed by the operator). The GitHub security advisory for MCP Inspector describes a lack of authentication between the Inspector client and proxy that let unauthenticated requests launch MCP commands over stdio, enabling remote code execution; it is rated critical and fixed in version 0.14.1 (June 2025). Source: GitHub Security Advisory (modelcontextprotocol/inspector maintainers) · evidence grade: primary · cited by Authenticate every agent tool server and verify every server an agent connects to