Analysis

Enterprise MCP security for Claude Code: Risks, governance, and best practices

Page published

Publication date unknown · First observed: 9 Oct 2026

Coverage timeline

9 Oct 2026fractal.aiobserved

Single-source analysis — one report is available.

Why it matters

MCP-connected coding agents like Claude Code expand an agent's reach into enterprise systems, so defenders need concrete governance and isolation controls to limit prompt injection, credential misuse, and data exfiltration risk.

Fractal's whitepaper examines enterprise security for Claude Code using the Model Context Protocol (MCP), outlining governance, identity-binding, least-privilege, and execution-isolation controls for connecting a coding agent to external tools and data. It advises treating tool metadata, retrieved content, and tool outputs as untrusted inputs, avoiding token passthrough, and applying risk-based permissioning, and it references Anthropic's Claude Code sandboxing (filesystem and network isolation) as a host-side safeguard against prompt-injected agents.