# #86 - MCP plugins: your next security blind spot? Page: https://stenobird.com/podcast/the-devsecops-talks-podcast-1222637/86-mcp-plugins-your-next-security-blind-spot Text version: https://stenobird.com/podcast/the-devsecops-talks-podcast-1222637/86-mcp-plugins-your-next-security-blind-spot.md Podcast: [The DevSecOps Talks Podcast](https://stenobird.com/podcast/the-devsecops-talks-podcast-1222637) Published: 2025-11-21T16:25:23+00:00 Episode link: https://devsecops.podbean.com/e/86-mcp-plugins-your-next-security-blind-spot/ Audio file: https://mcdn.podbean.com/mf/web/yav59mghnfkix817/086-mcp-plugins-your-next-security-blind-spot-.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/the-devsecops-talks-podcast-1222637/episodes/86-mcp-plugins-your-next-security-blind-spot Duration seconds: 3894 ## Resource Is MCP just another server you need to threat model, patch, and monitor? How do you keep users from over-privileged access, block LLM injection, and stop blind spots? We unpack the VentureBeat article https://venturebeat.com/security/mcp-stacks-have-a-92-exploit-probability-how-10-plugins-became-enterprise with real-world tips. We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.DevSecOps Talks podcast LinkedIn pageDevSecOps Talks podcast websiteDevSecOps Talks podcast YouTube channel ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/the-devsecops-talks-podcast-1222637/episodes/86-mcp-plugins-your-next-security-blind-spot/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/the-devsecops-talks-podcast-1222637/86-mcp-plugins-your-next-security-blind-spot.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.