MCP Security Working Group publishes threat model v1.0
The newly formed MCP Security Working Group released a formal threat model covering prompt injection via tool output, server supply-chain risks, and permission escalation. The document is now referenced by the official MCP specification as a non-normative companion.