AI agents need a way to reach outside tools and data. The connector that won that race is now the industry's biggest security blind spot.
MCP became the preferred standard for connecting AI agents to outside tools within 12 months of its release. By December 2025, it was used by every major coding assistant and most leading AI models.
How MCP Took Over So Fast
Anthropic launched MCP as an open standard in November 2024. By the following December, more than 10,000 active public MCP servers were running, backed by AWS, Google Cloud and Azure.
The advantage is simple. MCP lets an AI agent connect to multiple tools and data sources through one standard interface. That replaces a custom connector for each.
That speed came at a cost. Security defenses haven't kept pace with how fast AI agents now access sensitive systems dynamically.
What Actually Breaks
OWASP has flagged tool poisoning as a top concern. Malicious instructions get embedded inside a tool's description or return values to manipulate an agent's behavior.
Rug pull attacks are unique to this ecosystem. An attacker changes a tool's definition after a human has already approved it, exploiting the trust that approval created.
An analysis from Lakera, the AI security firm Check Point acquired in 2025, reviewed 10,000 MCP servers directly. Forty percent carried exploitable weaknesses.
The Miami Startup Already Working This Problem
That exact gap is the problem Miami-based Molt AI has built its platform around. It's testing what an AI agent actually did rather than trusting its own account of its actions.
Molt's MoltAIgent product uses cryptographic credentials and auditable actions to verify agent behavior directly. Most AI safety testing still just relies on a final answer review.
Molt sits inside a fast-growing category. Startups building agentic AI defenses raised a combined $3.6 billion this year, according to Crunchbase and CB Insights data. Six companies alone announced $392 million in new funding during a single week at RSAC 2026.
Why MCP Security Isn't the Whole Picture
Securing MCP connections addresses tool poisoning and unauthorized access directly. It doesn't cover every way an AI agent can reach outside systems.
Agents can still interact with tools and data without going through MCP at all. Evaluating any security vendor means checking how well it fits into a company's broader AI security stack. MCP coverage alone isn't enough.
What Happens If This Gap Doesn't Close
Security typically lags whenever infrastructure scales this fast. MCP is following the same pattern seen with earlier waves of enterprise software.
Which specific approach wins out matters less than whether the gap closes before a major MCP-specific breach forces the issue. For companies building on Miami's own AI infrastructure, that clock is already running.
OpenAI Ads Top $1B. Miami Marketers Take Note