Intermediate Any tool Explainer

MCP servers, explained

The standard plug that lets any AI assistant reach your files, tools and data, and what you're trusting when you use one.

Written against MCP protocol version 2026-07-28. Primitives have been deprecated between versions.

An MCP server is a small program that exposes something useful (your files, a database, an issue tracker) in a format any AI assistant can understand. The Model Context Protocol is the agreed format. Anthropic published it in November 2024 and handed it to the Linux Foundation’s Agentic AI Foundation in December 2025, and it lists ChatGPT, Gemini and Microsoft Copilot among the products that have adopted it.

Think of it as a USB-C port for AI applications: one shape of plug, many devices on either side. The current version of the specification is dated 28 July 2026, and as of 26 September nothing newer has replaced it.

The problem it solves

Before a shared protocol, every pairing of assistant and tool needed its own integration. Ten assistants and ten tools meant a hundred separate pieces of plumbing, each maintained by someone. A standard turns that multiplication into addition: write one server, and every assistant that speaks the protocol can use it.

What actually happens

Three parts, and the naming trips people up. The host is the application you actually use: Claude Desktop, VS Code, ChatGPT. The client is a connection the host creates, one per server, and you never touch it directly. The server is the program exposing the capability, and despite the name it usually runs on your own machine rather than somewhere remote.

A server can offer three kinds of thing. Tools are functions the model can call, like querying a database or filing a ticket. Resources are data it can read, like file contents. Prompts are reusable templates for common requests.

Local servers communicate over standard input and output; remote ones over HTTP, with OAuth for authorisation. The messages are JSON-RPC 2.0. When you connect one, the assistant asks what it offers, then decides for itself when something is relevant to what you asked.

What you are actually trusting

Every server you connect is code with real access, and a new route for prompt injection into whatever it can reach.

OWASP tracks a specific version of this called tool poisoning, and the gap it exploits is worth understanding. A server’s tool descriptions get inspected when you first connect. The responses those tools return go straight into the model’s context with no equivalent check. So a server can present harmlessly at setup and return hidden instructions later, once nobody is looking.

Connecting an MCP server is closer to installing a browser extension that can read your email than to adding a bookmark. Judge it on that basis.

The mitigations OWASP recommends are unglamorous and effective: connect only servers you have vetted, keep high-privilege tools out of reach of external ones, and require explicit confirmation before anything sensitive happens.

The protocol’s own maintainers are working on the identity side. Their August 2026 roadmap puts agent identity near the top, so that an agent can prove who it is “rather than pasted API keys and long-lived tokens”. Until that lands, a leaked key is as good as the agent it belonged to.

Where this leaves you

If you use an assistant that supports MCP, you probably already have servers connected. The useful first step is to find out which, and what each can reach. At work it may be arriving through Copilot: Copilot Studio lets colleagues add MCP servers to the agents they build, and since September 2026 Microsoft has offered to certify servers against its own checks for security and reliability, which is worth asking about before one is approved. For the wider picture of what happens once an assistant can act rather than answer, start with what people mean by AI agents.

Sources

Everything above was checked against these on 26 Sept 2026. Providers change things without notice. If a detail matters to a decision, follow the link.

  1. The 2026-07-28 SpecificationModel Context Protocol · 28 Jul 2026
  2. The New MCP RoadmapModel Context Protocol · 22 Aug 2026
  3. Model Context Protocol specification releasesGitHub
  4. Introducing the Model Context ProtocolAnthropic · 25 Nov 2024
  5. Donating the Model Context Protocol and establishing the Agentic AI FoundationAnthropic · 9 Dec 2025
  6. MCP tool poisoningOWASP
  7. New and improved: GitHub Copilot harness, agent skills, and richer contextMicrosoft Copilot Blog · 2 Sept 2026

Search