{"podcast":{"title":"Tech Lead Journal","slug":"tech-lead-journal-633005","podcast_index_feed_id":633005,"rss_url":"https://anchor.fm/s/265d7c64/podcast/rss","website_url":"https://techleadjournal.dev","image_url":"https://d3t3ozftmdmh3i.cloudfront.net/staging/podcast_uploaded_nologo/6336609/6336609-1773071114542-a0ddebae486f3.jpg","author":"Henry Suryawirawan","episode_count":276,"summary":"Great technical leadership requires more than just great coding skills. It requires a variety of other skills that are not well-defined, and they are not something that we can fully learn in any school or book. Hear from experienced technical leaders sharing their journey and philosophy for building great technical teams and achieving technical excellence. Find out what makes them great and how to apply those lessons to your work and team.","last_synced_at":"2026-07-14T00:21:08.354472+00:00","page_url":"https://stenobird.com/podcast/tech-lead-journal-633005"},"episode":{"title":"The MCP Security Risks You Can't Afford to Ignore","slug":"the-mcp-security-risks-you-can-t-afford-to-ignore","published_at":"2026-03-02T12:00:00+00:00","page_url":"https://stenobird.com/podcast/tech-lead-journal-633005/the-mcp-security-risks-you-can-t-afford-to-ignore","show_page_url":"https://stenobird.com/podcast/tech-lead-journal-633005","url":"https://podcasters.spotify.com/pod/show/techleadjournal/episodes/The-MCP-Security-Risks-You-Cant-Afford-to-Ignore-e3fns83","audio_url":"https://anchor.fm/s/265d7c64/podcast/play/116174531/https%3A%2F%2Fd3ctxlq1ktw2nl.cloudfront.net%2Fstaging%2F2026-1-28%2F418995705-44100-2-c5666602d74e3.mp3","summary":"What if the MCP server you installed last week is silently leaking your emails to a stranger? The AI tools boosting your productivity could already be your biggest security liability. MCP (Model Context Protocol) has quickly become the standard for connecting AI agents to external tools and data sources. But as adoption accelerates, so do the risks – from malicious servers harvesting your credentials in the background, to local processes exposed to your entire network with no authentication. Most developers install MCP servers without fully understanding what code is running or who wrote it, creating serious supply chain and shadow IT problems inside organizations. In this episode, Ariel Shiftan, CTO of MCPTotal, explains how MCP actually works, why there is a wide gap between its original design and how it is used in practice, and what that gap means for security. He also walks through real zero-days his team has discovered and shares practical advice for developers and enterprise leaders trying to adopt MCP without compromising their security posture. Key topics discussed: What MCP is and why it won the “USB for AI” race Why most MCP servers are just API wrappers done wrong Real zero-days found in popular, widely used MCPs How malicious MCPs can silently leak your credentials The supply chain risks hiding inside your dev toolchain Why banning MCP in your org is the wrong move Best practices for writing well-designed MCP servers Why agent permission prompts need better security defaults Timestamps: (00:00:00) Trailer &amp; Intro (00:02:49) What Is MCP and Why Is It Called the USB for AI? (00:07:22) How Does MCP Differ from Standard REST APIs? (00:13:40) What Can AI Agents Do with MCP Beyond Reading Data? (00:16:56) What Is RAG and How Did AI Evolve to Tool Calling? (0…","meta_description":"What if the MCP server you installed last week is silently leaking your emails to a stranger? The AI tools boosting your productivity could already be you…","key_points":[],"chapters":[],"topics":[],"duration_seconds":4339,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/tech-lead-journal-633005/episodes/the-mcp-security-risks-you-can-t-afford-to-ignore/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/tech-lead-journal-633005/the-mcp-security-risks-you-can-t-afford-to-ignore.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}