← Plugins

Explainer

What is MCP, and is it safe to connect your apps to AI?

Every time you connect Gmail, Google Drive or Notion to an AI assistant, you’re almost certainly using MCP. Here is what it is, why the names differ between companies, what has gone wrong, and the few habits that keep it safe.

Short answer

MCP is a plug, not a padlock. It’s the open standard that lets AI assistants use your apps. Connecting a well-known app from your assistant’s official directory, with approvals switched on, is low-risk. The real dangers are unknown servers or extensions, and hidden instructions inside emails, web pages or files the AI reads.

What MCP is, in one minute

Before MCP, every AI company had to build a separate link to every app. MCP — the Model Context Protocol — is one shared plug shape. An app builds one MCP server, and any assistant that speaks MCP can use it. A server offers three kinds of thing: tools (actions like “send a draft” or “create an event”), resources (data like files or messages) and prompts (ready-made templates).

DateMilestone
Nov 25, 2024Anthropic announces MCP as an open standard
Mar 26, 2025OpenAI adopts it reported
Apr 9, 2025Google says Gemini will support it reported
May 19, 2025Microsoft builds MCP into Windows 11
Dec 9, 2025MCP moves to the Agentic AI Foundation under the Linux Foundation, co-founded by Anthropic, Block and OpenAI

There are two kinds of server. Remote servers run on the app company’s computers; you sign in and they work on web, desktop and phone. Local servers run on your own computer and can reach your files — that’s more powerful and more risky.

Why every company calls it something different

CompanyWhat they call an MCP linkBundles of links + instructions
ClaudeConnectors (remote) · Desktop extensions (local)Plugins
ChatGPTApps (called connectors until late 2025)Plugins
GeminiConnected Apps; “custom apps” for your own MCP server (US only, 18+)— (skills, but no bundles for consumers)
Microsoft CopilotConnectors (free app, read-only); MCP plugins (business)Plugins (business, since Sep 30, 2026)

So “Claude connectors vs MCP” isn’t either-or: MCP is the plug standard; a connector is Claude’s name for one plugged-in app. The same goes for ChatGPT’s apps. Our Plugins guide has the full jargon decoder.

The real risks, in plain words

  1. Hidden instructions (prompt injection). Anything the AI reads — an email, a web page, a calendar invite, a document — can carry text telling it to do something else, like forwarding your files. Anthropic’s own example is invisible text in an email asking Claude to share your bank statements. Its defenses cut successful attacks to well under 1% in testing, but Anthropic says plainly: “The risk is not zero.”
  2. Poisoned tools. A server’s tool descriptions are read by the AI too. A malicious one can hide instructions there, and its developer can change the tools at any time after you approved them.
  3. Bad packages. Local servers are installed like software, and software can be malicious. The first malicious MCP server was found on the npm package site in September 2025.
  4. Too much access. Local extensions run with your computer account’s full permissions.

What has actually gone wrong

WhenWhat happenedLesson
May 2025Researchers showed a public GitHub issue could hijack an AI agent into leaking private code through GitHub’s MCP serverContent the AI reads can give it orders
Jul 2025A critical flaw in the popular mcp-remote tool (437,000+ downloads) let a malicious server run code on your computer; fixed in a later versionKeep tools updated
Sep 2025postmark-mcp, an email server on npm, behaved for 15 versions, then silently copied every email to an attackerA trusted package can turn bad in an update
Dec 2025Researchers modified a Claude skill to install ransomware after one approval (lab demo)Read a skill before you turn it on
Jan 2026Hidden white text in a Word file made Claude Cowork upload a user’s files to an attacker’s account, two days after launchUntrusted documents are untrusted input
Feb 2026A crafted calendar invite could make Claude desktop extensions run code; Anthropic said it was outside its threat model reportedLocal extensions deserve extra caution
Jun 2026Microsoft warned about poisoned MCP tool descriptions in the wild reportedWatch for tools that change

Several of these were security researchers’ demonstrations rather than attacks on real users; the npm package was a real attack.

Six rules that cover almost everything

  1. Install from your assistant’s own directory (Claude: Customize → Connectors; ChatGPT: Plugins in the sidebar). Prefer listings marked Verified — but know that Anthropic and OpenAI both say verification isn’t a full security audit.
  2. Read what it asks for. Read-only access to one folder is very different from “send email on your behalf”.
  3. Keep approvals on. Use “Allow once” instead of “Always allow” for anything that sends, deletes or buys.
  4. Connect only what you need, and disconnect what you stop using. In Claude: Customize → Connectors → Disconnect. Also remove the AI’s access in the app’s own security settings (for example your Google account’s third-party access list).
  5. Be careful what you point it at. Don’t ask an AI with access to your email or files to process documents or web pages from strangers.
  6. Treat local extensions and skills as software. Only from publishers you trust; read a skill’s instructions before switching it on.

One reassurance on privacy: Anthropic says raw content from connectors isn’t used to train its models unless you copy it into the chat. Your chats themselves follow your normal training setting — see how to switch that off.

Sources: MCP: introduction · Anthropic: MCP announcement · MCP joins the Agentic AI Foundation · MCP Registry · TechCrunch on OpenAI · TechCrunch on Google · Microsoft Windows blog · Anthropic: custom connectors · Anthropic: connector verification · Anthropic: using Claude in Chrome safely · Invariant Labs · JFrog · The Hacker News on postmark-mcp · Cato Networks · The Register on Cowork · LayerX · The Hacker News on Microsoft’s warning · Anthropic privacy center

Quick answers

What is MCP in simple terms?

MCP (Model Context Protocol) is an open standard that lets an AI assistant use another app’s tools and data. Its own documentation compares it to a USB-C port: one plug shape that works across many devices.

Who created MCP?

Anthropic announced it on November 25, 2024. OpenAI adopted it in March 2025, Google in April 2025 and Microsoft in May 2025. In December 2025 Anthropic donated it to the Agentic AI Foundation, part of the Linux Foundation.

Is a Claude connector the same as MCP?

A connector is Claude’s product name for one MCP connection to one service. Every Claude connector is MCP underneath, and you can add any remote MCP server’s address as a custom connector.

Is MCP safe?

MCP itself is a plug standard, not a safety guarantee. It’s as safe as the server you plug in and the permissions you approve. Official connectors from well-known companies, with approvals switched on, are low-risk for everyday use; unknown servers and hidden instructions in content are the real risks.

What is an MCP server?

A small program that offers an AI app a set of tools (actions), resources (data) and prompts for one service, in a format any MCP-compatible AI can use. Local servers run on your computer; remote ones run on the provider’s servers.

Is the official MCP Registry vetted?

No. The registry, still in preview in October 2026, stores where servers live and how to install them. It checks who owns a name but leaves security scanning to package registries and app marketplaces.

Keep learning