Explainer
What is MCP, and is it safe to connect your apps to AI?
Every time you connect Gmail, Google Drive or Notion to an AI assistant, you’re almost certainly using MCP. Here is what it is, why the names differ between companies, what has gone wrong, and the few habits that keep it safe.
MCP is a plug, not a padlock. It’s the open standard that lets AI assistants use your apps. Connecting a well-known app from your assistant’s official directory, with approvals switched on, is low-risk. The real dangers are unknown servers or extensions, and hidden instructions inside emails, web pages or files the AI reads.
What MCP is, in one minute
Before MCP, every AI company had to build a separate link to every app. MCP — the Model Context Protocol — is one shared plug shape. An app builds one MCP server, and any assistant that speaks MCP can use it. A server offers three kinds of thing: tools (actions like “send a draft” or “create an event”), resources (data like files or messages) and prompts (ready-made templates).
| Date | Milestone |
|---|---|
| Nov 25, 2024 | Anthropic announces MCP as an open standard |
| Mar 26, 2025 | OpenAI adopts it reported |
| Apr 9, 2025 | Google says Gemini will support it reported |
| May 19, 2025 | Microsoft builds MCP into Windows 11 |
| Dec 9, 2025 | MCP moves to the Agentic AI Foundation under the Linux Foundation, co-founded by Anthropic, Block and OpenAI |
There are two kinds of server. Remote servers run on the app company’s computers; you sign in and they work on web, desktop and phone. Local servers run on your own computer and can reach your files — that’s more powerful and more risky.
Why every company calls it something different
| Company | What they call an MCP link | Bundles of links + instructions |
|---|---|---|
| Claude | Connectors (remote) · Desktop extensions (local) | Plugins |
| ChatGPT | Apps (called connectors until late 2025) | Plugins |
| Gemini | Connected Apps; “custom apps” for your own MCP server (US only, 18+) | — (skills, but no bundles for consumers) |
| Microsoft Copilot | Connectors (free app, read-only); MCP plugins (business) | Plugins (business, since Sep 30, 2026) |
So “Claude connectors vs MCP” isn’t either-or: MCP is the plug standard; a connector is Claude’s name for one plugged-in app. The same goes for ChatGPT’s apps. Our Plugins guide has the full jargon decoder.
The real risks, in plain words
- Hidden instructions (prompt injection). Anything the AI reads — an email, a web page, a calendar invite, a document — can carry text telling it to do something else, like forwarding your files. Anthropic’s own example is invisible text in an email asking Claude to share your bank statements. Its defenses cut successful attacks to well under 1% in testing, but Anthropic says plainly: “The risk is not zero.”
- Poisoned tools. A server’s tool descriptions are read by the AI too. A malicious one can hide instructions there, and its developer can change the tools at any time after you approved them.
- Bad packages. Local servers are installed like software, and software can be malicious. The first malicious MCP server was found on the npm package site in September 2025.
- Too much access. Local extensions run with your computer account’s full permissions.
What has actually gone wrong
| When | What happened | Lesson |
|---|---|---|
| May 2025 | Researchers showed a public GitHub issue could hijack an AI agent into leaking private code through GitHub’s MCP server | Content the AI reads can give it orders |
| Jul 2025 | A critical flaw in the popular mcp-remote tool (437,000+ downloads) let a malicious server run code on your computer; fixed in a later version | Keep tools updated |
| Sep 2025 | postmark-mcp, an email server on npm, behaved for 15 versions, then silently copied every email to an attacker | A trusted package can turn bad in an update |
| Dec 2025 | Researchers modified a Claude skill to install ransomware after one approval (lab demo) | Read a skill before you turn it on |
| Jan 2026 | Hidden white text in a Word file made Claude Cowork upload a user’s files to an attacker’s account, two days after launch | Untrusted documents are untrusted input |
| Feb 2026 | A crafted calendar invite could make Claude desktop extensions run code; Anthropic said it was outside its threat model reported | Local extensions deserve extra caution |
| Jun 2026 | Microsoft warned about poisoned MCP tool descriptions in the wild reported | Watch for tools that change |
Several of these were security researchers’ demonstrations rather than attacks on real users; the npm package was a real attack.
Six rules that cover almost everything
- Install from your assistant’s own directory (Claude: Customize → Connectors; ChatGPT: Plugins in the sidebar). Prefer listings marked Verified — but know that Anthropic and OpenAI both say verification isn’t a full security audit.
- Read what it asks for. Read-only access to one folder is very different from “send email on your behalf”.
- Keep approvals on. Use “Allow once” instead of “Always allow” for anything that sends, deletes or buys.
- Connect only what you need, and disconnect what you stop using. In Claude: Customize → Connectors → Disconnect. Also remove the AI’s access in the app’s own security settings (for example your Google account’s third-party access list).
- Be careful what you point it at. Don’t ask an AI with access to your email or files to process documents or web pages from strangers.
- Treat local extensions and skills as software. Only from publishers you trust; read a skill’s instructions before switching it on.
One reassurance on privacy: Anthropic says raw content from connectors isn’t used to train its models unless you copy it into the chat. Your chats themselves follow your normal training setting — see how to switch that off.
Sources: MCP: introduction · Anthropic: MCP announcement · MCP joins the Agentic AI Foundation · MCP Registry · TechCrunch on OpenAI · TechCrunch on Google · Microsoft Windows blog · Anthropic: custom connectors · Anthropic: connector verification · Anthropic: using Claude in Chrome safely · Invariant Labs · JFrog · The Hacker News on postmark-mcp · Cato Networks · The Register on Cowork · LayerX · The Hacker News on Microsoft’s warning · Anthropic privacy center
Quick answers
What is MCP in simple terms?
MCP (Model Context Protocol) is an open standard that lets an AI assistant use another app’s tools and data. Its own documentation compares it to a USB-C port: one plug shape that works across many devices.
Who created MCP?
Anthropic announced it on November 25, 2024. OpenAI adopted it in March 2025, Google in April 2025 and Microsoft in May 2025. In December 2025 Anthropic donated it to the Agentic AI Foundation, part of the Linux Foundation.
Is a Claude connector the same as MCP?
A connector is Claude’s product name for one MCP connection to one service. Every Claude connector is MCP underneath, and you can add any remote MCP server’s address as a custom connector.
Is MCP safe?
MCP itself is a plug standard, not a safety guarantee. It’s as safe as the server you plug in and the permissions you approve. Official connectors from well-known companies, with approvals switched on, are low-risk for everyday use; unknown servers and hidden instructions in content are the real risks.
What is an MCP server?
A small program that offers an AI app a set of tools (actions), resources (data) and prompts for one service, in a format any MCP-compatible AI can use. Local servers run on your computer; remote ones run on the provider’s servers.
Is the official MCP Registry vetted?
No. The registry, still in preview in October 2026, stores where servers live and how to install them. It checks who owns a name but leaves security scanning to package registries and app marketplaces.
Keep learning
Are AI browser extensions safe? Every major incident since 2023, and a 9-point check
Fake ChatGPT extensions, chat-harvesting add-ons and hijacked AI sidebars: what went wrong, why a Featured badge isn’t proof, and 9 checks before installing.
Custom GPTs are retiring on December 11, 2026. Here’s what happens to yours
OpenAI is retiring custom GPTs on Dec 11, 2026 and turning them into plugins. What transfers, what doesn’t (actions, sharing), and what to do now.
Plugins, skills, apps, connectors: what each one is in ChatGPT, Claude, Gemini and Copilot
ChatGPT plugins vs skills, connectors vs apps, Claude connectors vs MCP, Gems vs skills: one plain-English decoder for 2026, with the dates each name changed.