Skip to content

← All Q&A

What is MCP and what security risk did Salesforce discover when they opened one?

AI ProductRisks

Drawn from Lutz Finger's Forbes column, LinkedIn writing, and Cornell teaching. Sources are cited inline so you can read the originals.

Opening your platform to AI agents expands your attack surface immediately.

MCP stands for Model Context Protocol. It is the basis of the new user of SaaS platforms. Publishing an MCP endpoint means expanding the attack surface of your platform. Salesforce learned this directly: within weeks of launching Agentforce, researchers disclosed a critical vulnerability. Salesforce acted and built a governance layer on top: Agent Fabric and Trusted Agent Identity. This makes clear SaaS is needed as a trusted, governed layer that raw vibecoded alternatives can never be.

— SaaSpocalypse Is Dead - The Future Of SaaS Is SaaS · Forbes


Have a follow-up? hello@lutzfinger.com. Or pick another question: all Q&A →