Securing AI Agents: How to See MCP Servers and A2A Traffic with Salt Security
AI agents have moved past conversation into action. They book transactions, pull sensitive data, and chain tools together through the Model Context Protocol (MCP) and Agent-to-Agent (A2A) traffic. Every one of those actions runs on APIs, and that connective tissue is where the risk sits. Salt Security Co-Founder and CEO Roey Eliyahu and VP of Product Strategy Nick Rago walk through the risks in the agentic action layer and show what Salt does about them.
Roey frames the three buckets of risk that AI agents create: an expanding attack surface, sensitive data leakage through connected systems, and new attacks against the MCP protocol itself. He lays out five questions every organization should ask about its agents, covering capability, reach, data access, posture, and bad actors. Nick then maps the crowded AI security field, where close to 200 companies now claim a focus, and explains why most of them secure the model while the action layer stays exposed.
The session uses concrete examples, including the Chevrolet dealership chatbot tricked into a $1 car offer and a walkthrough of an agentic hospital where a triage agent could order and ship a prescription. The live product demo shows how Salt inventories agentic actions, flags unauthenticated MCP servers, applies out-of-the-box agentic AI posture policies, and detects behavioral anomalies like an MCP server accessed 176 times against a normal baseline.
Speakers:
- Roey Eliyahu, Co-Founder & CEO of Salt Security
- Nick Rago, VP of Product Strategy at Salt Security
Salt Security created the API security category and built the OWASP API Top 10. The platform gives security teams one inventory of APIs and MCP servers across cloud and on-premise environments, with visibility, governance, and threat protection for AI agents deployed as critical infrastructure.
Run a free external attack surface assessment: https://salt.security/attack-surface
Timestamps:
0:00 Third webinar on securing agentic AI
1:45 The AI revolution and the API security problem
4:35 AI agents, LLMs, and MCP servers defined
6:24 Before and after: how MCP transforms your architecture
8:30 The API fabric and its sharp expansion
9:37 Three buckets of risk: attack surface, data leakage, new attacks
11:44 Five questions to ask about your AI agents
13:50 Mapping the AI security landscape
16:32 The agentic AI life cycle, from model to action
20:42 Model security versus the agentic action layer
24:56 The Chevy dealership $1 car prompt injection
27:27 Agentic General Hospital: unintended actions and attack surface
31:56 Shadow MCP servers and internal exposure
33:51 How Salt secures the agentic action layer
36:00 Product demo: bringing the API fabric to life
38:20 AI policy compliance and building your own policies
40:57 Behavioral threat protection for MCP traffic
42:33 Why agents as critical infrastructure carry the real risk
44:44 Q&A: context management, on-prem, SIEM, and local MCP servers
55:28 Analyst perspectives and free resources