AI Agent & Copilot
  • Home
  • Exclusives
  • Podcast
  • Microsoft Analysis
  • Reports
  • Events
    • 2026 Event
    • 2025 Event Videos
  • Tech Analysts
  • Summit NA
  • Partner Executive Summit
  • AI Agent & Copilot Summit
AI Agent & Copilot
  • Exclusives
  • Podcast
  • Microsoft Analysis
  • Reports
  • Events
    • 2026 Event
    • 2025 Event Videos
  • Tech Analysts
  • Login / Join

    A confirmation code will be emailed when setting up your account or resetting your password—check spam if needed.no-reply@dynamicscommunities.com

AI Agent & Copilot
  • Login / Join

    A confirmation code will be emailed when setting up your account or resetting your password—check spam if needed.no-reply@dynamicscommunities.com

Home » Cisco Secures MCP Servers With Multiple Scanning Engines, Supply Chain Protections
Cloud Wars Minute

Cisco Secures MCP Servers With Multiple Scanning Engines, Supply Chain Protections

Tom SmithBy Tom SmithDecember 5, 2025Updated:December 8, 20252 Mins Read
Facebook Twitter LinkedIn Email
To adjust the volume hover the cursor over the volume bar
Share
Facebook Twitter LinkedIn Email

Welcome to this AI Agent & Copilot Podcast, where we analyze the opportunities, impact, and outcomes that are possible with AI.

In this episode, I speak with Cisco’s Arjun Sambamoorthy, senior director, AI, about Model Context Protocol security and Cisco’s new MCP Scanner product.

Highlights

Risks With AI Agents and MCP (01:15)

Sambamoorthy explains the risks associated with MCP and AI agents, including supply chain and runtime perspectives. He highlights the risk of compromised MCP servers, similar to typical software compromises. The three main types of risks are tool poisoning attacks, rug-pull attacks, and over-privileged tools.

Rug pull attacks exploit the trust established after tool authorization by changing tool descriptions or implementations. Tool poisoning attacks involve altering the behavior of large language models through tampered tool descriptions.

Agent Supply Chain and MCP Scanner Benefits (03:38)

Sambamoorthy compares the AI agent supply chain to the traditional software supply chain, emphasizing the importance of static and semantic analysis. He discusses the need for contextual inspection of tools before integrating them with LLMs.

Sambamoorthy explains MCP Scanner’s unique capabilities, focusing on analyzing tool descriptions and ensuring alignment with tool implementations. He highlights the open-source nature of the MCP scanner, which includes three different scanning engines. Open source offers affordability and flexibility, allowing users to integrate various AI models, while maximizing accessibility.

Vulnerability Checks and Threat Taxonomy (08:20)

Discussing the vulnerability checks that MCP Scanner performs, Sambamoorthy outlines its threat taxonomy, which includes 15 different threat categories, such as tool poisoning attacks, tool exploitation, and injection attacks. The MCP scanner analyzes tool descriptions for poisoning and prompt injection, ensuring semantic safety. It also checks the code implementation for alignment with tool descriptions and behavioral safety.

Partnerships and Integration with Major Vendors (10:29)

Cisco’s engagements in the software ecosystem include the open-source community — integrating the MCP scanner in CI/CD pipelines and MCP registries. He provides an example of Turbo MCP, which uses the MCP scanner in its CI/CD pipeline. He also references a partnership with AWS to integrate the MCP scanner into AWS’s open-source MCP registry and MCP gateway. He closes by emphasizing the importance of using MCP responsibly.

AI Agent & Copilot Summit is an AI-first event to define opportunities, impact, and outcomes with Microsoft Copilot and agents. Building on its 2025 success, the 2026 event takes place March 17-19 in San Diego. Get more details.

ai ai agent Cybersecurity featured supply chain
Share. Facebook Twitter LinkedIn Email
Analystuser

Tom Smith

Analyst
Cloud Wars, Agent and Copilot

Areas of Expertise
  • LinkedIn

  Contact Tom Smith ...

Related Posts

Microsoft Targets the Agentic Marketing Economy With Expanded Publicis Alliance

April 17, 2026

Claude Code Enhancements Make It Routine for Developers to Reuse Their Automations

April 17, 2026

Microsoft Introduces Hybrid AI Automation in Copilot Studio

April 17, 2026

Microsoft’s Governance Toolkit Addresses Top AI Agent Risks, Positions Customers for Success

April 17, 2026
Add A Comment

Comments are closed.

Community Summit NA 2026

Gaylord Opryland Resort
      Nashville, TN
October 11–15, 2026

The largest independent Microsoft AI & Business Applications User Conference on the planet. Four days of big ideas, education, training, networking and more to define your relevance in the AI era. Register Now

Recent Posts
  • Microsoft Targets the Agentic Marketing Economy With Expanded Publicis Alliance
  • Claude Code Enhancements Make It Routine for Developers to Reuse Their Automations
  • Microsoft Introduces Hybrid AI Automation in Copilot Studio
  • Microsoft’s Governance Toolkit Addresses Top AI Agent Risks, Positions Customers for Success
  • Microsoft Enhances Copilot Studio With Deeper Integration of Agents Into Core Business Processes

  • Newsletter
  • Event Sessions
  • AI Reports
  • Exclusive Interviews

Join Today

Advertisement
AI Agent & Copilot
  • Home
  • Privacy Policy
  • Contact Us
  • AI Agent & Copilot Summit
© 2026 AI Agent and Copilot

Type above and press Enter to search. Press Esc to cancel.