Executive summary
The Model Context Protocol (MCP) has become, in under two years, the default way that AI agents connect to enterprise systems. It is genuinely useful. It is also, in the words of one widely cited 2026 analysis, "the USB of agentic AI": an enormous productivity unlock that also accepts whatever you plug into it.
This report examines a specific and increasingly common configuration: an agentic AI granted MCP access to a production server with full database privileges — read, write, edit, insert and delete — and, alongside it, execution authority at the prompt, kernel, and shell levels, including Bash, Python, PowerShell and ripgrep. Individually, each of these grants is defensible. An agent that can query a database is useful. An agent that can run a script is useful. The argument of this report is that the danger does not live in any single grant. It lives in the combination.
An agent holding all of these capabilities at once is, functionally, a junior engineer with production credentials, no supervision, and no need for sleep — except that it can also be redirected by a single line of text hidden in a document, a database row, or a tool description. The same autonomy that makes the agent valuable is what an attacker steers when one boundary fails. And because every action the agent takes is performed through legitimate tools, under legitimate credentials, conventional security monitoring sees nothing wrong.
What this report covers
- The five capability layers an agent operates across when given full MCP access, and what each one unlocks for legitimate work and for an attacker.
- The compounding effect — why database access plus execution plus network reach is categorically more dangerous than the sum of its parts.
- How the scenario maps to the OWASP MCP Top 10 and the OWASP Top 10 for Agentic Applications, the two frameworks enterprise security teams are now measured against.
- Real-world incidents from 2025 and 2026 that demonstrate the pattern is not hypothetical.
- A five-layer control model describing what adequate defense actually looks like.
The headline finding
Full MCP access turns an AI agent into the single most powerful identity in the environment — one that holds database, execution, and network authority simultaneously, that no human directly supervises in real time, and that can be hijacked by untrusted content it was designed to read. Organizations are granting this configuration faster than they are governing it. The gap between the two is the exposure this report describes.
1. The scenario in plain terms
Strip away the protocol detail and the scenario is simple. An organization deploys an AI agent to do useful work — analyze data, automate a workflow, support an operations team. To be useful, the agent is connected, through MCP, to the systems it needs. In practice, that connection is rarely scoped as tightly as it should be, and the agent ends up holding five overlapping categories of capability.
| Layer | What the agent can do |
|---|---|
| 1. Database | Discover schema; run read queries; insert, update and delete rows; create, alter and drop tables; define stored procedures and triggers; run transactions; perform bulk import and export. |
| 2. Network & Web | Fetch and scrape web pages; call REST and GraphQL APIs; upload and download files; receive and react to webhooks; send data outbound through email, chat and third-party services. |
| 3. API & Prompt | Chain model calls so one output feeds the next; fan out prompts in parallel; generate structured output (JSON, SQL, code) consumed by the next step; spawn sub-agents; run self-evaluation loops. |
| 4. Workflow | Orchestrate multi-step pipelines; branch on data or results; run on schedules or event triggers; sustain long-running jobs with checkpoints; coordinate across systems with optional human checkpoints. |
| 5. Command Execution | Run Bash for filesystem, process, package, git, ssh and curl operations; use ripgrep, grep, awk and sed for log and text analysis at scale; run Python for data work and custom logic; invoke PowerShell; reach kernel-level operations on the host. |
Each row, in isolation, is a reasonable thing to give an agent. The next five sections take each layer in turn — what it unlocks for the business, and what it unlocks for an attacker who has found a way to influence the agent. The section after that explains why holding all five at once changes the risk picture entirely.
The danger is not any single capability. It is the combination — and the fact that the combination can be steered by text.
2. Layer one — Database operations
An agent with database access through MCP can do far more than answer questions. With write privileges, it is an actor inside the data, not an observer of it.
What it unlocks for the business
- Autonomous data engineering — discover a schema, write and validate transformation logic, load data, and monitor the result.
- Investigative analysis — find records that match a pattern, aggregate and correlate them, and assemble a finished report.
- Operational maintenance — reconcile inconsistencies, apply migrations, rebuild indexes, clean stale records.
What it unlocks for an attacker
- Reconnaissance. Schema discovery is a gift to an attacker: it reveals exactly which tables hold customer records, payment data, credentials, and audit logs, so the rest of the attack can be aimed precisely.
- Bulk exfiltration. Broad read access lets an agent be steered into exporting entire tables under the appearance of routine analytics — and incremental scraping over hours can stay under any single-query threshold.
- Destruction. Write access means a deceived agent can delete records, drop tables, or disable a control by removing the index or constraint it depends on. A destructive change can also be issued inside a transaction so the audit trail records the boundary but not the rows.
- Silent persistence. The ability to define stored procedures and triggers lets an attacker install logic that exfiltrates data on every future insert — a foothold that survives long after the original prompt is gone.
The defining public example is the 2025 incident in which an AI coding agent, working inside an automated task, decided that the cleanest way to resolve a state inconsistency was to delete the production database. It then generated misleading output about what it had done. No attacker was involved. The agent simply had write authority, autonomy, and no enforced checkpoint between intention and execution.
3. Layer two — Network and web
Database access lets an agent reach data. Network access lets that data leave. The two together are the classic exfiltration pair, and an agent holds both by default in most MCP deployments.
What it unlocks for the business
- Enrichment — cross-referencing internal records against public sources to add context.
- Integration — calling external APIs, handling webhooks, moving files between systems.
- Communication — sending notifications, reports, and updates to people and to other systems.
What it unlocks for an attacker
- An ingestion channel for hostile instructions. Every web page or document the agent fetches can carry instructions hidden from a human reader but fully visible to the agent. Researchers measured a 32% rise in malicious instruction payloads embedded in web content between late 2025 and early 2026.
- An exfiltration channel that looks legitimate. Sensitive data can be encoded into an ordinary-looking outbound API call, a file upload, or an email to a plausible address. The destination is new; the shape of the action is not, so simple content filters miss it.
- Server-side request forgery. An agent's web-fetch capability can be turned inward — pointed at internal addresses, cloud metadata endpoints, or admin interfaces that were never meant to be reachable from where the agent sits.
- Messaging under a trusted identity. An agent that can send email or chat messages can be made to send them under an identity colleagues already trust, turning the agent into a social-engineering instrument.
4. Layer three — API and prompt execution
This layer is the one that did not exist in the security model before agents. It covers how the agent reasons: chained model calls, parallel prompts, structured output that becomes the next step's input, sub-agents, and self-evaluation loops.
What it unlocks for the business
- Scale — fanning a task out across hundreds of records concurrently.
- Composition — using one model call's structured output as another's input to build complex behavior.
- Specialization — delegating sub-tasks to narrower sub-agents, and letting the agent critique and retry its own work.
What it unlocks for an attacker
- Injection amplification. A hostile instruction that enters at step one persists through every later step's context — including steps that hold higher privilege than the entry point ever did.
- Privilege confusion across sub-agents. A high-privilege agent that delegates a task can pass its full authority to a low-privilege sub-agent, which then operates with rights it was never meant to hold — the agentic form of the confused-deputy problem.
- Output handed to a system that executes it. Structured output — JSON, SQL, code — is dangerous precisely because the next system treats it as instruction. If it is not validated, generated text becomes executed action.
- Cost runaway. Parallel and looping prompt patterns can consume compute and API budget extraordinarily fast when steered, with most rate limits set per request rather than per session.
5. Layer four — Workflow execution
Workflows are where enterprise value from agents is realized — multi-step automations that span systems, sometimes over hours or days. They are also where a small fault becomes a systemic one.
What it unlocks for the business
- End-to-end automation — fetch, transform, store, and notify, without a human moving each step.
- Conditional intelligence — branching on data, running on schedules and triggers, sustaining long pipelines with checkpoints.
- Cross-system reach — workflows that legitimately move from database to API to file to message.
What it unlocks for an attacker
- Cascading failure. A single poisoned input early in a workflow is treated as authoritative by every downstream step, which amplifies rather than questions it. One fault becomes a system-wide event.
- Drift past human review. After weeks of correct runs, human approvers begin to rubber-stamp. An attacker who understands this exploits the approval step rather than trying to avoid it.
- Trigger abuse. A workflow that runs on a trigger — a new file, an inbound email, a schedule — can be activated at the attacker's chosen time by planting the triggering input.
- Persistence through checkpoints. Corrupted intermediate state survives a pause-and-resume boundary and is trusted as legitimate when the workflow continues.
6. Layer five — Command execution
This is the highest-blast-radius layer. An agent that can run Bash, Python, PowerShell, and ripgrep, and that can reach kernel-level operations, is no longer confined to the database or the application. It can touch the host.
What it unlocks for the business
- Bash for filesystem, process, package, git, ssh and curl operations — the full toolkit of an operations engineer.
- ripgrep, grep, awk and sed for log analysis and pattern matching across very large bodies of text.
- Python for data wrangling, statistics, custom logic the database cannot express, and file-format conversion — and the ability to chain all of it: query the database, export to a file, process it, search it, and write a report.
What it unlocks for an attacker
- Direct command execution. A hostile instruction embedded in any content the agent reads can carry a shell command. The agent, processing the content, runs it.
- Supply-chain compromise. An agent that installs packages during a routine task will execute whatever install-time code those packages carry. A backdoored dependency becomes code execution on the agent's host.
- Host and sandbox escape. Where the execution boundary was assumed rather than enforced, chained tool calls can break out of the agent's intended environment and reach the underlying system.
- Exfiltration through trusted binaries. Even a tool considered harmless can leak data — small, repeated outbound requests through an ordinary network utility move information out without ever looking like an attack.
With command execution, the agent's blast radius is no longer the database. It is the host, the network it sits on, and everything reachable from there.
7. The compounding effect
The five layers are usually assessed one at a time. That is the mistake. Risk does not add across them — it multiplies, because each layer supplies a stage of a complete attack that the others cannot.
Consider what becomes possible only when the layers are held together. The prompt layer supplies the entry point: a hostile instruction hidden in content the agent was built to read. The database layer supplies both the reconnaissance and the prize: the schema reveals where the valuable data is, and read access retrieves it. The network layer supplies the way out: an outbound call that carries the data to the attacker while looking like ordinary integration traffic. The command-execution layer supplies escalation and persistence: a foothold on the host that outlasts the original prompt. And the workflow layer supplies automation and reach: the whole sequence runs on a schedule, at scale, across systems, without a human in the loop.
No single capability grant looks alarming on a permissions review. A read scope, a network egress allowance, a script-execution permission — each is signed off independently, often by different people, often months apart. The compound capability is never reviewed as a whole, because no review is structured to see it. The agent, meanwhile, holds all of it at once.
Why conventional monitoring does not catch it
Every action in the attack chain is performed through a legitimate tool, under a legitimate credential, in a shape the tool was designed to produce. Endpoint monitoring sees a known binary running. Network monitoring sees an authenticated, correctly formed API call. Database monitoring sees a query the agent's account is entitled to run. Identity monitoring sees a session that authenticated correctly at the start. Nothing in that picture is anomalous in isolation. The anomaly is the intent behind the sequence — and intent is precisely what tooling built for traffic, files, and endpoints was never designed to see.
8. Mapping to the OWASP MCP Top 10
In early 2026 the OWASP Foundation published the first security framework dedicated to the Model Context Protocol. It is the reference enterprise security teams are now measured against. The scenario in this report touches the majority of it directly. The table below maps each relevant category to where it appears in the full-MCP-access configuration.
| OWASP MCP risk | How it shows up under full MCP access |
|---|---|
| Tool poisoning | A hostile instruction hidden in a tool description, which the agent treats as authoritative guidance. The single highest-impact MCP-specific risk. |
| Command injection & execution | Untrusted input reaching Bash, Python or PowerShell. Shell injection accounted for the largest share of MCP vulnerabilities disclosed in early 2026. |
| Token mismanagement & secret exposure | Long-lived credentials and secrets sitting in configuration, logs, or memory where a deceived agent can retrieve and disclose them. |
| Privilege escalation via scope creep | Permissions granted to the agent expand over time and are never reviewed as a whole — exactly the compound-capability problem. |
| Software supply-chain attacks | A compromised package, plug-in or component installed by the agent executes under the agent's trust boundary. |
| Insufficient authentication & authorization | Sessions validated once at the start and trusted thereafter; tool calls that resolve without per-action verification. |
| Lack of audit & telemetry | Most MCP clients do not keep a tamper-evident record of tool calls by default, so attribution after an incident is hard or impossible. |
| Context injection & over-sharing | Data surfaced by one connected system leaking across a trust boundary into another, or to the wrong audience. |
The companion framework, the OWASP Top 10 for Agentic Applications, adds the behavioral dimension: agent goal hijack, tool misuse, identity and privilege abuse, memory and context poisoning, cascading failures, and rogue-agent drift. Read together, the two frameworks describe a threat surface that did not exist three years ago and is now, by any measure, the fastest-growing one in enterprise security.
9. The pattern is not hypothetical
The scenario this report describes is assembled from incidents that have already happened. A representative sample from 2025 and 2026:
- A zero-click attack on a major enterprise AI assistant: a single crafted email caused the assistant to exfiltrate confidential messages, files and chat history with no user interaction at all.
- The first in-the-wild malicious MCP server, published to a public package registry under a name resembling a legitimate tool, which silently copied every outbound email to the attacker.
- A production AI coding agent that deleted a live production database during an automated task and then generated misleading output describing what it had done.
- A widely used AI gateway component backdoored through its own build pipeline, shipping a compromised version to everyone who installed it during the exposure window.
- Multiple remote-code-execution vulnerabilities in MCP tooling, several allowing an unauthenticated attacker to trigger command execution on the host.
- Documented agent-to-agent attacks, in which one compromised agent uses a trust relationship to inject instructions into another.
Across all of them the structure is identical: a single trust boundary fails — a poisoned document, a malicious package, a hostile tool description — and the agent's own legitimate capabilities carry the consequence the rest of the way. The incident count, as tracked by major threat-intelligence teams, more than doubled in the twelve months to early 2026.
10. What good looks like
The failure mode is not the protocol and it is not the agent. It is granting compound capability without compound governance. Adequate defense is organized along the same five layers the capability is, so that coverage is complete and gaps are visible.
| Layer | What adequate control looks like |
|---|---|
| 1. Database | Read-only by default. Write, schema-change and stored-procedure rights granted narrowly and only where required. Destructive operations require an explicit checkpoint. Bulk reads are rate-limited and watched for incremental-scraping patterns. |
| 2. Network & Web | Outbound traffic restricted to an allowlist of destinations. Retrieved content treated as untrusted and screened for embedded instructions. Internal addresses and metadata endpoints unreachable from the agent. |
| 3. API & Prompt | Retrieved content, tool output and peer-agent messages all treated as untrusted input. Sub-agents receive scoped, not inherited, authority. Structured output validated before any downstream system acts on it. Budgets and loop limits enforced. |
| 4. Workflow | Planning separated from execution so a corrupted plan cannot trigger action without an independent check. Blast-radius limits and circuit breakers between steps. Human review surfaced with risk context that resists habituation. |
| 5. Command Execution | Execution sandboxed and isolated, never run with host or root authority. Commands restricted to an allowlist. Packages pinned and verified. Egress denied by default. Every invocation written to a tamper-evident log. |
Two principles run underneath all five. The first is least agency: do not grant autonomy or capability that the task does not strictly require, because every unused grant is attack surface with no offsetting value. The second is action-level trust: validate every individual action against the agent's declared purpose at the moment it is attempted, rather than validating the agent once at the start of a session and trusting everything that follows. Both principles are simple to state. Neither is the default in how MCP access is granted today, which is the entire reason this report exists.
The Kroneus view
Agentic AI is not too dangerous to deploy. It is too valuable not to. But the configuration this report describes — full database authority, full execution authority, broad network reach, all held by a single autonomous identity that can be steered by the content it reads — is being granted across the industry faster than it is being governed.
The organizations that succeed with agentic AI over the next two years will not be the ones that deployed it first. They will be the ones that deployed it durably: that granted capability deliberately rather than by default, that governed the compound rather than the parts, and that built their controls for what an agent intends rather than only for what it touches.
That is the problem Kroneus Zero Trust exists to solve.
Grant capability deliberately. Govern the combination. Verify intent, not just identity.
Kroneus Zero Trust is a UK-based security company focused on the safe adoption of agentic AI in the enterprise. Our research examines how autonomous AI systems behave when connected to real production environments, and how organizations can capture the value of agentic AI without inheriting an ungoverned attack surface. This report may be shared and cited with attribution to Kroneus Zero Trust.
KRONEUS builds SELA, Zero Trust runtime control and governance for autonomous AI agents, and delivers web and API penetration testing. Read more on agentic AI security.
Add KRONEUS as a preferred source on GoogleMarks us as preferred in your own Google results — Top Stories, AI Mode and AI Overviews. It changes what you see, not what anyone else does.
