KSKS Security Research
Learning map / Session 2 / Scenes 09–11

SECURITY 03 · CONNECTED CONTEXT

Every connection adds context.Every context adds a trust boundary.

Threat-model capability connections, retrieved evidence, tool outputs, and durable memory as separate trust and data-governance boundaries.

MCP securityRAG poisoningmemorytool security
Learning guide
Level
Applied
Reading time
13 min
Presentation
Session 2
Progress
3 of 6

01 · Mental model

Connection, retrieval, and persistence fail differently

An MCP server can expose unexpected capabilities or return hostile content. Retrieval can surface poisoned, stale, or access-inappropriate passages. Tool results can contain injection payloads or malformed data. Memory can preserve a malicious or incorrect state long after the original input disappears.

Secure each boundary with identity, allowlists, provenance, schema validation, access-aware retrieval, content labelling, TTL and deletion rules, environment separation, and monitoring for capability or data changes.

02 · Visual explanation

01MCP servercapability provenance
02Tool resultschema + content
03Retrieval corpusaccess + freshness
04Memory storeTTL + deletion
05Run contextminimum necessary
Four connected trust boundariesA common protocol does not create common trust; each source needs its own assurance and policy.

03 · Compare and decide

Control the boundary that actually changed

Decision lensPrimary threatControl emphasis
MCPUntrusted server or capability changeServer allowlist, versioning, consent, scoped transport
Tool outputMalformed or adversarial observationSchema, size, content and destination validation
RAGPoisoned or overshared evidenceProvenance, ACL filtering, freshness, citation
MemoryPersistent false or sensitive stateTyped fields, source, TTL, user control, deletion

04 · Cybersecurity example

A poisoned runbook becomes durable memory

A retrieved runbook tells the agent to bypass an approval and the agent stores that as a future preference.

01

Retrieval marks source and trust level.

02

Policy blocks instruction-like content from becoming memory.

03

Memory accepts only typed, user-owned fields.

04

A security signal records the rejected persistence attempt.

Outcome: The attack is contained before it outlives the original retrieval event.

05 · What to remember

The 60-second recall

01

MCP is a protocol, not a trust decision.

02

Memory writes need stricter controls than temporary context.

03

Provenance and access filters must survive retrieval and handoff.

Teach-back prompt: Explain this concept to a teammate using the diagram, then name one failure mode and the control that stops it.

06 · Questions people ask

FAQ

No. Store the minimum durable state needed for the workflow, with explicit purpose, source, ownership, TTL, and deletion behavior.

07 · Primary sources

Continue with authoritative guidance