MCP Security at Wiz with Rami McCarthy
Episode
54 min
Read time
2 min
Topics
Artificial Intelligence, Product & Tech Trends
AI-Generated Summary
Key Takeaways
- ✓AI Secrets Leakage: Four out of five new public repository secrets are AI-related, driven by LLMs generating hardcoded credentials and AI tools using plain text configuration files without established secret scanning coverage for emerging platforms.
- ✓MCP Local Server Risk: Organizations should maintain small allowlists of approved MCP servers tied to reputable organizations, treating them like Chrome extensions with permissioning models rather than allowing unrestricted consumption of 4,000+ available servers from unvetted sources.
- ✓Auto-Approval Vulnerability: Running MCP clients with auto-approval enabled eliminates human oversight that catches indirect prompt injection attacks, where malicious prompts embedded in GitHub issues can trigger unintended actions without user intervention or detection.
- ✓Supply Chain Attack Pattern: The TJ Actions compromise demonstrates multi-step attacks where attackers compromise less popular actions to gain access to widely-used dependencies, requiring organizations to monitor not just direct dependencies but entire upstream chains.
What It Covers
Rami McCarthy from Wiz discusses Model Context Protocol security risks, AI-generated code vulnerabilities, secrets leakage patterns, GitHub Actions supply chain attacks, and practical security guidance for organizations adopting AI development tools.
Key Questions Answered
- •AI Secrets Leakage: Four out of five new public repository secrets are AI-related, driven by LLMs generating hardcoded credentials and AI tools using plain text configuration files without established secret scanning coverage for emerging platforms.
- •MCP Local Server Risk: Organizations should maintain small allowlists of approved MCP servers tied to reputable organizations, treating them like Chrome extensions with permissioning models rather than allowing unrestricted consumption of 4,000+ available servers from unvetted sources.
- •Auto-Approval Vulnerability: Running MCP clients with auto-approval enabled eliminates human oversight that catches indirect prompt injection attacks, where malicious prompts embedded in GitHub issues can trigger unintended actions without user intervention or detection.
- •Supply Chain Attack Pattern: The TJ Actions compromise demonstrates multi-step attacks where attackers compromise less popular actions to gain access to widely-used dependencies, requiring organizations to monitor not just direct dependencies but entire upstream chains.
Notable Moment
McCarthy reveals that academic research shows roughly one quarter to one third of AI-generated code snippets contain security vulnerabilities when sufficiently complex, requiring the same security scaffolding and review processes as human-written code.
Episode Transcript
Wiz is a cloud security platform that helps organizations identify and remediate risks across their cloud environments. The company's platform scans layers of the cloud stack, including virtual machines, containers, and serverless configurations to detect vulnerabilities and misconfigurations in context. The model context protocol or MCP is emerging as a potential standard for connecting LLM applications to external data sources and tools. It has rapidly gained traction across the industry with broad backing from companies such as OpenAI, Microsoft, and Google. While the protocol offers great opportunities, it also introduces certain security risks. Rami McCarthy is a principal security researcher at Wiz. He joins the podcast with Gregor Vann to talk about security research, AI and secrets leakage, MCP security, supply chain attacks, career advice, and more. Gregor Vand is a CTO and founder currently working at the intersection of communication, security, and AI and is based in Singapore. His latest venture, wintik.ai, reimagines what email can be in the AI era. For more on Gregor, find him at van.hk or on LinkedIn. Hello. Welcome to Software Engineering Daily. My guest today is Rami McCarthy from Wiz. So hi, Rami. Thanks for coming on. Thanks for having me. Excited to be here. Yeah. Very excited to have to have you here. And as I sort of just mentioned, you're here on effectively behalf of Wiz. We you joined fairly recently, but you definitely have quite a illustrious past in the security world, a lot of research that I'm sure a lot of our audience will be familiar with whether sort of directly or indirectly. So I think it'd be kind of just fun if you could just pretty much take us through kind of your kind of journey from whether it's, you know, high school or college through to through to where you are at the moment. Awesome. Yeah. You mentioned I joined Wiz recently, and I really feel like that is a logical culmination of a lot of what I've done in my career. I studied security in in university. Academically, I feel like I came up at a really good time where those programs were starting to pop up in The US. Specifically, the NSA was funding a lot of universities to have really good cybersecurity programs. And I stumbled my way into security consulting and pen testing, which gave me the chance to see hundreds of different security programs and also sort of sparked this pattern of research that has pulled forward into now being in a purely research role. In fact, at NCC group, where I was a consultant, Clint Gibler, who does TLDR sec was one of the research directors and was frankly, the person who got me going down this route and is someone I've had, you know, the joy to work with consistently since. After consulting, I moved in house to a small health tech where I got to help build a security program, sort of from not day zero, but from day …
Get the full transcript (10,046 words) + summary by email — free
One-time email with the complete transcript and AI summary of this episode. No account needed.
One email, no spam. We’ll also show you what SignalCast does.
You just read a 3-minute summary of a 51-minute episode.
Get Software Engineering Daily summarized like this every Monday — plus up to 2 more podcasts, free.
Pick Your Podcasts — FreeKeep Reading
More from Software Engineering Daily
A Rust Framework to Simplify Distributed Systems
Sep 10 · 50 min
Syntax
973: The Web’s Next Form: MCP UI (with Kent C. Dodds)
Jan 26
More from Software Engineering Daily
SED News: The NVIDIA-Hugging Face Deal, China’s Proxy Economy, the Open Weight Surge
Sep 8 · 52 min
Cognitive Revolution
AI:AM Highlights: Recursive Self-Improvement, Rushed and Vibe-Coded?
Aug 28
More from Software Engineering Daily
We summarize every new episode. Want them in your inbox?
A Rust Framework to Simplify Distributed Systems
SED News: The NVIDIA-Hugging Face Deal, China’s Proxy Economy, the Open Weight Surge
Moving Beyond RAG with Precomputed Context
The Death of Online Anonymity
TypeScript 7 and What Comes Next
Similar Episodes
Related episodes from other podcasts
Syntax
Jan 26
973: The Web’s Next Form: MCP UI (with Kent C. Dodds)
Cognitive Revolution
Aug 28
AI:AM Highlights: Recursive Self-Improvement, Rushed and Vibe-Coded?
a16z Podcast
Aug 11
The CISO Playbook for AI Agents | Datadog
a16z Podcast
Aug 4
OpenAI's Joshua Achiam: Did We Already Reach AGI?
a16z Podcast
Jul 26
Ben Horowitz: The Fight Over Open Source AI
Explore Related Topics
This podcast is featured in Best Cybersecurity Podcasts (2026) — ranked and reviewed with AI summaries.
Read this week's AI & Machine Learning Podcast Insights — cross-podcast analysis updated weekly.
You're clearly into Software Engineering Daily.
Every Monday, we deliver AI summaries of the latest episodes from Software Engineering Daily and 192+ other podcasts. Free for one show.
Start My Monday DigestNo credit card · Unsubscribe anytime