MCP Security Kit by Agent Trust Cloud

high

Remote MCP server over unencrypted http

A remote (non-localhost) MCP server is reached over http:// instead of https://.

Why it matters

Tool calls, results and any tokens travel in clear text, so anyone on the network path can read or change them.

How to fix it

Use an https:// endpoint. If the server is internal, put it behind TLS anyway.

Before

{
  "mcpServers": {
    "reports": {
      "url": "http://mcp.internal.example.com/sse"
    }
  }
}

After

{
  "mcpServers": {
    "reports": {
      "url": "https://mcp.internal.example.com/sse"
    }
  }
}

Illustrative configs. The checker flags the “before” version with this finding and not the “after” version.

Check your own config

Other checks