Module 05 of 8~16 minPro
Securing MCP Servers: Permissions, Least-Privilege, and Sandboxing
The spine of the course. The confused-deputy and prompt-injection threat model, permission-approval workflows, least-privilege tool scoping, sandboxing shell and file access, auth, and the OpenClaw and DOCKER-USER hardening lessons. What you should never give a server access to.
§ You will learn
- Articulate the MCP threat model: why a server is both a confused deputy and a prompt-injection surface, and what that means for tool design.
- Apply least-privilege scoping to tools, file access, and shell access so a compromised prompt cannot do maximum damage.
- Secure remote MCP servers with bearer-token auth, a reverse proxy, allowlists, and host-level firewall rules that catch Docker-exposed ports.
- Design permission-approval workflows that survive restarts and stay usable for always-on agents.
§ Sealed entry
This module is part of the Pro record.
5 sections · ~16 min · objectives above are the preview