Model Context Protocol is usable in the enterprise, but tool discovery must be treated as untrusted ingress. A tool’s description, and any later change to it, can carry instructions the model will follow, so tools cannot be trusted on name alone. Public U.S. National Security Agency guidance on MCP recommends inspecting every tool schema before it reaches the model. In practice, run that inspection and exposure management inside a security control plane, pin and review tool definitions, and give agents least-privilege access to only the tools a task requires.