WebMCP Security: When “Agent-Ready” Websites Become an Attack Surface (And How to Ship Tools Safely)
WebMCP makes it easier for AI agents to interact with your site—but it also creates a clean delivery path for prompt injection through the tools you expose. Here’s what changed, why it matters for SMEs, and a practical playbook to threat-model, label, and restrict tools before an agent (or a bad actor) uses them against you.