16 items in AI Security
An MCP gateway's real job is to enforce, at your boundary, controls the Model Context Protocol already makes mandatory. That makes the strongest evaluation questions conformance questions with verbatim answers in the spec — not feature questions, where every vendor says yes. The current revision also changed the session model and deprecated a registration mechanism, so shortlists assembled from 2025 material are testing for the wrong things.
The current OWASP list for LLM applications is the 2025 edition, and its first entry is still prompt injection — a class OWASP itself says has no fool-proof prevention. This guide works from that admission: what the platform guardrails from AWS, Microsoft, and Anthropic actually screen (and what their own docs say they skip), which architectural controls survive a bypassed filter, how to red-team the result, and what belongs at the API edge.