Describes AI Semantic Inspection Report in Cisco Secure Access. As enterprises rapidly adopt AI agents to automate and optimize business operations, many are using the Model Context Protocol (MCP) to enable AI agents to access data and perform reasoning tasks in a standardized way.
As enterprises rapidly adopt AI agents to automate and optimize business operations, many are using the Model Context Protocol (MCP) to enable AI agents to access data and perform reasoning tasks in a standardized way. Because these tools often handle mission-critical enterprise data, ensuring visibility, security assurance, threat protection, and prevention of data breaches is essential. Securing interactions between AI agents (acting as MCP clients) and enterprise systems is a key challenge in deploying agentic AI safely.
Overview
Cisco Secure Access introduces the MCP Semantics Inspection Proxy, designed to analyze MCP protocol messages between AI agents/applications and MCP servers. This proxy identifies and blocks suspicious or policy-violating requests and responses, mitigating threats such as prompt injection, tool poisoning, reconnaissance, and data exfiltration that exploit MCP server-side vulnerabilities.
The Secure Access AI Semantics Inspection Dashboard provides visibility into detected threats by showing the number of blocked MCP messages and allowing users to drill down into detailed event reports. Threat detection and blocking are enabled by default for all MCP traffic, requiring no additional configuration or installation on client endpoints or MCP servers.
Key Features
-
Semantic Inspection Proxy: Analyzes MCP traffic flowing through Secure Access, detecting MCP messages for risky actions such as prompt injection, tool poisoning, and data exfiltration, performed by the AI agents.
-
Verdict Assignment: The semantic inspection proxy works in conjunction with Cisco Foundation AI model to assign each MCP message a verdict of Block or Allow.
-
Logging and Insights: MCP messages are logged on each observed MCP server, with actionable insights displayed to users.
-
AI Semantic Inspection dashboard: The AI Semantic Inspection dashboard on Secure Access provides visibility into detected threats, MCP server endpoint URLs and allows users to drill down into details about the security events.
-
Automatic Protection: Threat detection and blocking operate automatically on all MCP traffic visible to Secure Access, without client-side dependencies.
Current Scope and Constraints
-
This version inspects MCP requests only for agents accessing MCP servers publicly hosted on the internet, such as GitHub, Slack, Atlassian, Langchain, or Playwright.
-
Inspection applies to MCP traffic entering Secure Access via Remote Access VPN, SD-WAN, or IPSec/CNHE tunnels.
-
There is no dependency on client-side software; any MCP traffic visible to Secure Web Gateway (SWG) is analyzed.
Requirements for AI Semantic Inspection
To enable AI Semantic Inspection for your organization, follow these steps:
-
Configure a Security Profile for internet access with Decryption and AI Semantic Inspection enabled. For detailed guidance, refer to the documentation on Security Profiles for Internet Access.
-
Create at least one internet access rule that allows traffic and applies the Security Profile with Decryption enabled. See Security Profile for instructions.
-
Ensure MCP traffic inspection is enabled on Remote Access VPN connections and Branch office connections to Secure Access via SD-WAN or IPsec tunnels.
Detection of Specific Threats and Security Risks
Cisco Secure Access intercepts and evaluates MCP messages between MCP clients and servers to identify security risks and threats. These are consolidated into four key categories:
-
Data Exfiltration: Attempts to extract, export, or transfer sensitive data such as credentials, personally identifiable information (PII), training data, customer data, or internal datasets. This includes risks like data exposure via agent tooling, training data leaks, and intellectual property compromise.
-
Prompt Injection: Attempts to override instructions, jailbreak the AI model, or manipulate system or developer directives. This category covers direct prompt injection and jailbreak attempts aimed at altering AI behavior.
-
Tool Poisoning: Attempts to compromise tools, plugins, configurations, or the supply chain by embedding hidden instructions, backdoors, or persistence mechanisms. This includes tool exploitation, supply chain compromise, configuration persistence, and protocol manipulation.
-
Tool Shadowing: Attempts to register a tool with the same name as a legitimate tool so the agent resolves to the attacker’s version, enabling call interception, data theft, or false result injection without detection.
View AI Semantic Inspection Events in Reports
-
For more information, see View the AI Semantic Inspection Report.
-
For more information, see View AI Semantic Inspection Events in Activity Search Report.