Skip to main content
All posts

Agentic SecurityAnnouncement: June 30, 20263 min read

A remote MCP connection is an access decision. What should you check?

Google Cloud's new remote MCP server lets external agents reach cloud tools. The useful security question is which identity, permissions, and actions that connection carries.

Two illuminated data buildings connected by a single cyan line across a glass bridge.

A remote MCP connection lets an AI agent use tools across a network. Before enabling one, identify the agent's identity, the tools it can call, the cloud resources it can reach, and where its actions will be recorded. A convenient connector can also widen the path from a developer's workstation to production resources.

On June 30, Google Cloud described a remote Model Context Protocol (MCP) server for its Gemini Enterprise Agent Platform. It lets external development tools, including coding agents, interact with platform resources. Google listed toolsets for models, prompts, evaluation, notebooks, endpoints, and other functions. It also described Agent Registry for discovery and Cloud IAM Deny policies for restricting access. Those are Google Cloud product capabilities, not controls automatically supplied by every MCP connection.

Four checks before connecting an agent

  1. Step 01Identify the caller. Which user or service account authorizes the agent, and can that identity be distinguished from other agents using the same connector?
  2. Step 02List the enabled tools. A model lookup and an endpoint-management action have different consequences. Give the agent only the toolsets its task requires.
  3. Step 03Limit the resources. Check project, dataset, notebook, and endpoint permissions at the cloud service as well as in the agent's own configuration.
  4. Step 04Record the action. Keep the agent, tool, target resource, access decision, and outcome linked so a reviewer can reconstruct what happened.

Consider a coding agent asked to inspect an evaluation result. It may need read access to a result and perhaps to a model description. It does not follow that it should be able to change a deployed endpoint or run a notebook. Review permissions by task, then test what the connector actually permits. An agent's written instructions are useful, but the service's access controls decide what it can do.

Where Hikma fits

HikmaAI can assess supported MCP surfaces and apply controls to protected interactions. The first step is still an accurate inventory of each connection and its permissions. Start with one agent, one task, and the smallest set of tools that completes it; expand only after you can review the resulting actions.

See how HikmaAI finds risk, enforces protection and produces evidence on a representative production flow.