{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/mcp-security-landscape-survey-2025/",
 "asOf": "2026-09-26",
 "id": "mcp-security-landscape-survey-2025",
 "date": "2025-03-30",
 "datePrecision": "day",
 "title": "Survey maps Model Context Protocol landscape, server lifecycle and security risks",
 "lane": "defense",
 "kind": "paper",
 "summary": "Hou, Zhao, Wang and Wang survey MCP's architecture, industry adoption and server lifecycle. The first version (March 2025) split the lifecycle into creation, operation and update phases and discussed security risks in each. A revision in October 2025 expanded this to four phases with 16 activities and a threat taxonomy of four attacker types and 16 threat scenarios, with case studies and per-phase safeguards.",
 "whyItMatters": "It was an early systematic threat model for MCP as tool connectors spread through agent products.",
 "actors": [],
 "topics": [
  "tool-and-mcp-security",
  "agent-supply-chain"
 ],
 "atlas": [
  "tools",
  "supply-chain",
  "credentials"
 ],
 "artifacts": [
  "model-context-protocol"
 ],
 "sources": [
  {
   "url": "https://arxiv.org/abs/2503.23278",
   "publisher": "arXiv",
   "title": "Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions",
   "date": "2025-03-30",
   "type": "primary",
   "accessed": "2026-09-25"
  },
  {
   "url": "https://arxiv.org/abs/2503.23278v3",
   "publisher": "arXiv",
   "title": "Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions (v3)",
   "date": "2025-10-07",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "v1 (30 March 2025) defines a three-phase MCP server lifecycle (creation, operation, update) and discusses nine security risks, three per phase.",
   "locator": "v1 abstract; Section 5"
  },
  {
   "fact": "v3 (7 October 2025) taxonomy covers four attacker types (malicious developers, external attackers, malicious users, security flaws) and 16 threat scenarios across a four-phase, 16-activity lifecycle.",
   "locator": "v3 abstract; Section 1"
  }
 ],
 "significance": 2,
 "fideQuestions": [],
 "methods": [
  "tool-poisoning"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}