Model Context Protocol (MCP) Connectors
Claude, ChatGPT, and other AI assistants increasingly connect to real systems through the Model Context Protocol (MCP), rather than just answering from what you type. This guide covers what MCP is, and what to check before you trust a connector.
What is an MCP Connector?
The Model Context Protocol (MCP) is a shared set of rules that allows AI apps to connect to outside data, software systems, and tools in the same way every time.
A MCP connector lets an AI assistant reach into a real data source or system (e.g., your email, a shared drive, a calendar) instead of just answering a question. Think of it like handing someone a key. A good connector opens one specific room for one specific reason, not the whole building. Connectors often assume the person’s identity and can potentially access any files or use any permissions the person has. That's what makes connectors useful, and it's also why they deserve a second look before you turn one on.
Security and Trust Considerations
You may encounter risks while interacting with various MCP connectors, including:
Hidden instructions in tools
Content a connector retrieves, such as files, emails, or webpages, can also contain hidden instructions that the AI may follow as if they came from you. For example, a malicious email could direct the AI to locate sensitive files and send them out through what looks like a routine action.
Changes after approval
A server that looks clean at approval time can later change its tool descriptions to add malicious behavior. Most clients don't re-prompt when a description changes.
Content a connector retrieves, such as files, emails, or webpages, can also contain hidden instructions that the AI may follow as if they came from you. For example, a malicious email could direct the AI to locate sensitive files and send them out through what looks like a routine action.
Server impersonation to steal data
When several servers are connected at once, a less secure server can be used to sneak in hidden instructions that trick the model into how it uses a separate, trusted server.
Confused deputy problems
A server acts with its own broad privileges rather than the requesting user's, so a trick that fools the model can cause the server to overstep.
Credential and token handling
Most MCP servers still use permanent, unchanging passwords instead of more secure, time-limited logins. So if one of those passwords ever leaks, everything it has access to is at risk.
Supply chain issues
Unmaintained or unreviewed packages, path traversal, and command injection bugs are plain old software vulnerabilities wearing a new interface.
Best Practices for the Stanford Community
Anyone who uses a connector helps keep it safe. Here's what we expect from you:
Use trusted connectors only
Use only connectors from the AI vendor, your school or department's IT team, or built in-house. Avoid anything shared informally online or from an unknown author. Before you connect, verify the connector is on the Available Connectors page for the AI tool you're using and that the data is within the risk level the AI tool is approved for.
If it isn't listed, submit a ServiceNow request for that AI tool, including the connector's URL and your use case. Connectors that involve High Risk data may also need a Data Risk Assessment (DRA).
Read before you connect
Check what a connector can access and do (read-only vs. write, send, or execute) before you approve it. Grant only the minimum access required.
Adjust the access, don’t just accept it
Many connectors let you limit what AI is allowed to do. For example, you can allow it to write but not delete. Grant only the access you need and check in from time to time on whether you still need it. If you start using it for a new purpose or with more sensitive data, confirm the AI tool is approved for that data’s risk level.
Skip auto-approve or YOLO modes
Don't use auto-approve or YOLO modes (running with the --dangerously-skip-permissions flag) on accounts, devices, or data you can't afford to lose or expose. If you need them, use an isolated sandbox with no access to sensitive data.
Match the tool to your data's risk level
Check the GenAI Tool Matrix before connecting anything to Moderate or High Risk data. Approval for one tool doesn't carry over to another.
Don't move data down the risk ladder
Don't let a tool pull High Risk data (PHI, FERPA records) and hand it off to a tool that's only approved for Low or Moderate Risk. See Stanford's risk classifications.
Treat changes as unreviewed
If a connector updates or suddenly asks for new access, check it again before trusting it, don't assume it's still safe.
Review each connector separately for each AI tool
Approving a connector in Claude doesn't approve it in ChatGPT or Gemini. Know who owns each connector. Every connector in use needs a named, accountable owner.
Know who owns each connector
Every connector in active use has a named owner who is accountable for it. If you're not sure who that is, ask before you keep using it. If you're the owner, you're the person others will come to when something goes wrong.
Report anything that seems off
If a connector asks for new permissions or behaves unexpectedly, pause and take a second look before you keep using it. If anything seems off, submit a ticket to the Information Security Office.
Manage connectors across their full lifecycle
Approving a connector shouldn't be the last time anyone looks at it. Check connectors before first use, again after every update or new access request, and periodically while in use. Disconnect connectors you no longer need. A forgotten connector nobody's watching is a lingering risk.
