AI applications are increasingly operating across enterprise systems. They can retrieve documents, post messages, query databases, invoke APIs and make changes to cloud infrastructure. The Model Context Protocol (MCP) is quickly becoming a standard way to connect these applications to the tools and data required to perform that work. As those connections multiply, security teams need to answer three questions: Which MCP servers are actually running, what can they access, can we stop an unsafe action before it causes damage?
Sweet answers those questions using live runtime traffic. Sweet automatically discovers MCP servers, AI agents, and shadow AI usage, then connects that activity to the surrounding cloud envirnoment, and finally enforces guardrails as agents act. Sweet users get an inventory based on what is actually running, the context required to understand the risk and the ability to do something about it.
What Is an MCP Server?
Think of MCP as a universal adapter for AI applications. Without a common standard, developers may need to build a separate integration every time they want an AI application to communicate with an external system. MCP gives these applications a consistent way to use tools and access data. An MCP server might allow an agent to search Google Drive, update a ticket, query a database or interact with cloud infrastructure. This reduces the work required to give AI applications useful capabilities, which helps explain MCP’s rapid adoption. By December 2025, Anthropic reported more than 10,000 active public MCP servers and over 97 million monthly SDK downloads.
The same efficiency that makes MCP useful also creates a security challenge. Every new connection can introduce another identity, credential, permission and route to sensitive data or production systems. Some MCP servers will be deployed through approved development processes. Others may appear as teams experiment with AI tools, leaving security responsible for connections it never knew existed.
MCP Servers Are an Attack Vector
An MCP server sits at an important point in the execution chain. It gives an AI application the tools needed to turn a decision into an action. If that server is malicious, compromised or given excessive access, a legitimate AI workflow can become a path to data theft or cloud compromise.
The malicious postmark-mcp package demonstrated this risk. The package impersonated Postmark and built trust across 15 versions. Version 1.0.16 then introduced a backdoor that secretly copied outgoing emails to an external server. The expected workflow continued to function, but sensitive information could leave the organization through a hidden BCC. Postmark advised users to remove the package, review their email logs and rotate potentially exposed credentials. Prompt injection creates another path. An attacker can place instructions inside a document, support ticket, webpage or database record that an agent is expected to retrieve. If the agent interprets those instructions as part of its task, it may use an MCP tool to access data or take an action that the user never requested.
In both cases, the initial connection may appear legitimate. The risk becomes clear only when the MCP server is used and intent turns into action - that makes runtime an essential control point.
Sweet Discovers MCP Servers from Live Traffic
Security cannot protect an MCP server it does not know exists. Static inventories and developer questionnaires only show what teams have documented. Sweet discovers MCP servers directly from live traffic, showing customers what is actually communicating inside their environment. There is no separate deployment required for this capability. Sweet uses its runtime sensor and integrated AI Gateway to identify AI agents, MCP servers and shadow AI activity while connecting agent interactions and prompts to the applications and cloud resources around them.
Customers gain a continuously updated inventory showing where each MCP server runs, the cloud account it belongs to and when it was last observed. This replaces assumptions with evidence from the production environment.

Discovery tells you that an MCP server exists. Cloud context tells you why it matters. Sweet maps each server to its workload, vulnerabilities, detections, models, data connections and surrounding cloud services. A server with limited access in an isolated development environment represents a very different risk from one connected to sensitive data and production infrastructure. Sweet gives teams that distinction without requiring them to manually reconstruct it across multiple tools.

Enforce the Boundary in Runtime
Visibility helps a security team understand an agent, but runtime enforcement keeps that agent within its intended purpose. Sweet can inspect agent interactions, understand the prompts and tools involved, and apply guardrails while the agent is operating. If a shopping assistant attempts to retrieve credentials from the cloud instance metadata service, for example, Sweet can recognize that the request falls outside the agent’s intended role and block it before it executes. Legitimate shopping activity can continue without interruption.

Secure MCP in the Context of Your Cloud
MCP is helping AI applications perform useful work across the enterprise. Securing it requires more than an inventory of known servers or an alert after an agent has already acted. Sweet discovers MCP servers and AI activity from live traffic, shows customers what each server can reach in the cloud and blocks unsafe behavior as it happens. You know what is running, understand the risk in its full context, and retain control when an agent moves beyond its intended purpose.
That is how organizations can adopt MCP without losing control of the systems it connects. If you want to see how Sweet secures MCP servers from live runtime traffic, request a demo.



