# Organizations Strengthen MCP Security Controls

An October 6, 2026, SC Media commentary warns that MCP URL elicitation can reduce credential exposure to AI clients while shifting phishing risk to the browser destination. For government buyers and contractors evaluating agentic AI systems, the security issue is whether MCP servers, browsers, and connected identity and network tools can enforce approved destinations and provide correlated logs. The article identifies no specific government procurement, contract, or solicitation.

- Organizations using agentic AI should set approved destination-domain policies for each MCP server and review destination changes as new capabilities.
- Procurement teams can use these controls as evaluation criteria for MCP-enabled solutions, including the ability to correlate logs across the agent, MCP server, browser, proxy, and identity provider.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity, Artificial Intelligence
**Published:** October 06, 2026

### Sources
- [MCP fixed secret handling. URL elicitation moved the phishing risk into the browser | perspective | SC Media](https://www.scworld.com/perspective/mcp-fixed-secret-handling-url-elicitation-moved-the-phishing-risk-into-the-browser) - SC Media