Recommended guardrail
Authenticate every agent tool server and verify every server an agent connects to
Require authentication on every MCP, A2A, or tool-server endpoint, including local development proxies, and have agents reach remote servers only over TLS with credentials. Detect tool servers listening on all interfaces without authentication and agent configurations that reach remote servers over plain HTTP or without credentials. Package and publisher verification is covered by guardrail.agent-component-provenance; an agent's own identity by guardrail.agent-identity-and-action-traceability.
This is TwinEthos's opinion of what a responsible AI integration does anyway. It is never a legal or standards requirement; where binding law applies, the law governs.
The recommended-guardrail rule files are open under CC BY 4.0; attribution and scope are in the terms.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Evidence grade
Standards consensus (2)
2 standards and frameworks · 2 graded incidents.
TwinEthos recommendation, not law. Where binding law applies, the law governs. No binding law in the corpus requires this control yet. 2 standards and frameworks recommend it (IMDA Agentic AI MGF, NIST AML Taxonomy (AI 100-2e2025) — Agentic). 2 graded incidents cited.
Standards and frameworks
- Every AI agent should have a distinct identity and its actions should be traceable to a supervising human (Singapore (SG); IMDA MGF for Agentic AI (v1.5) — Section 2.1.2, Agent identity and authorisation; cited)
- AI agents should mitigate indirect prompt injection and agent hijacking (NIST AI 100-2e2025) (NIST AML Taxonomy (AI 100-2e2025) — Agentic; NIST AI 100-2e2025, Secs. 3.4 (Indirect Prompt Injection Attacks and Mitigations), 3.5 (Security of Agents) and 3.6 (Benchmarks for AML Vulnerabilities); cited)
Family “An AI agent's authority, reach, inputs, and components are not bounded and accountable”: binding law on related controls is in force in no jurisdiction. Context only: it does not change this guardrail's grade.
Graded incidents
- Internet-exposed MCP servers without authentication (2025-07; confirmed) Trend Micro research (researcher publication) · evidence grade: primary
- MCP Inspector proxy accepted unauthenticated requests to launch MCP commands (CVE-2025-49596) (2025-06-13; disclosed by the operator) GitHub Security Advisory (modelcontextprotocol/inspector maintainers) · evidence grade: primary
The guard to add
Require a verified token on every MCP or tool-server endpoint, and connect agents to remote servers only over HTTPS with credentials to a fixed, configured URL.
Server side: every MCP, A2A, or tool server validates a bearer token before any tool runs (FastMCP token_verifier= with auth=AuthSettings(...), or an auth middleware in front of the endpoint), and binds to 127.0.0.1 rather than 0.0.0.0 unless authentication is configured; local development proxies follow the same rule. Client side: each remote server entry in .mcp.json or agent config, and each streamablehttp_client / StreamableHTTPClientTransport call, uses an https:// URL fixed in configuration (never taken from model output or retrieved content) and sends credentials via an Authorization header or OAuth.
Example (MCP Python SDK (FastMCP)), before:
mcp = FastMCP('files', host='0.0.0.0')
mcp.run(transport='streamable-http')After:
from mcp.server.auth.settings import AuthSettings
from pydantic import AnyHttpUrl
# JwtVerifier: our TokenVerifier subclass that checks signature, audience, and expiry
mcp = FastMCP('files', host='0.0.0.0', token_verifier=JwtVerifier(JWKS_URL),
auth=AuthSettings(issuer_url=AnyHttpUrl('https://auth.example.com'),
resource_server_url=AnyHttpUrl('https://files.example.com/mcp'),
required_scopes=['files:read']))
mcp.run(transport='streamable-http')Control: Agent tool servers or agent peers not authenticated. Engineering guidance, not legal advice.
Why
Tool servers are how agents act, so an unauthenticated server can let anyone invoke an agent's tools, and an agent that does not check which server it reached can be steered by an impostor. The maintainers of an MCP developer tool have disclosed a flaw that let unauthenticated requests launch commands, and a security firm found MCP servers reachable from the internet without authentication.
Class: agent security · set: agent containment · maturity: reviewed · confidence: high · id guardrail.agent-tool-server-authentication