Research Note

MCP Meeting Workflow Security Research Note

Model Context Protocol standardizes how an AI application discovers and invokes capabilities. It does not decide whether a capability is trustworthy, appropriate, or auth

Aug 4, 20261 min readBy Dalton Anderson
In this article

MCP Meeting Workflow Security Research Note

Model Context Protocol standardizes how an AI application discovers and invokes capabilities. It does not decide whether a capability is trustworthy, appropriate, or authorized for a particular meeting.

The current MCP server concepts documentation distinguishes resources, prompts, and schema-defined tools. The November 2025 specification uses JSON Schema and defines an authorization framework for HTTP transports.

The official MCP security guidance requires explicit consent around local server commands and describes OAuth, redirect, and confused-deputy risks. OWASP's MCP security guidance adds tool poisoning, over-scoped credentials, cross-server escalation, untrusted results, and package-supply-chain risk.

A meeting agent should inventory every read and write tool, isolate privileged capabilities, bind credentials to the intended server and user, validate parameters and results, preview consequential calls, and log the final outcome. Tool descriptions and returned text are untrusted inputs.

Sources

Follow the evidence.

  1. query-focused meeting summarization researchaclanthology.org
  2. reader-focused meeting summarization researchaclanthology.org
  3. AI RMF Measure playbookairc.nist.gov
  4. OWASP's MCP security guidancecheatsheetseries.owasp.org
  5. key-management guidancecsrc.nist.gov
  6. server conceptsmodelcontextprotocol.io
  7. authorization guidemodelcontextprotocol.io
  8. security guidancemodelcontextprotocol.io
  9. MCP specificationmodelcontextprotocol.io
  10. device encryption guidancecisa.gov
  11. local-first software essayinkandswitch.com
  12. 18 U.S.C. 2511law.cornell.edu
  13. California Penal Code section 632leginfo.legislature.ca.gov
  14. meeting recap studymicrosoft.com
  15. agent identity and authorization concept papernccoe.nist.gov
  16. agent evaluation worknist.gov
  17. SP 800-209nist.gov
  18. current About pagequillmeetings.com
  19. data sovereignty pagequillmeetings.com
  20. current Quill documentationquillmeetings.com

From this episode

Two useful next steps.

Evergreen · 1 min

Why Generic Meeting Summaries Fail Different Readers

A useful meeting recap preserves one shared decision record while giving each participant the evidence, commitments, risks, and next context their role needs.

Evergreen · 1 min

What Is an AI Chief of Staff? A Practical Definition

An AI chief of staff prepares context, tracks commitments, recommends next steps, drafts work, and uses approved tools without inheriting human authority.

Return to the episode