Securing AI Agents: How to See MCP Servers and A2A Traffic with Salt Security

AI agents have moved past conversation into action. They book transactions, pull sensitive data, and chain tools together through the Model Context Protocol (MCP) and Agent-to-Agent (A2A) traffic. Every one of those actions runs on APIs, and that connective tissue is where the risk sits. Salt Security Co-Founder and CEO Roey Eliyahu and VP of Product Strategy Nick Rago walk through the risks in the agentic action layer and show what Salt does about them.

Roey frames the three buckets of risk that AI agents create: an expanding attack surface, sensitive data leakage through connected systems, and new attacks against the MCP protocol itself. He lays out five questions every organization should ask about its agents, covering capability, reach, data access, posture, and bad actors. Nick then maps the crowded AI security field, where close to 200 companies now claim a focus, and explains why most of them secure the model while the action layer stays exposed.

The session uses concrete examples, including the Chevrolet dealership chatbot tricked into a $1 car offer and a walkthrough of an agentic hospital where a triage agent could order and ship a prescription. The live product demo shows how Salt inventories agentic actions, flags unauthenticated MCP servers, applies out-of-the-box agentic AI posture policies, and detects behavioral anomalies like an MCP server accessed 176 times against a normal baseline.

Speakers:

  • Roey Eliyahu, Co-Founder & CEO of Salt Security
  • Nick Rago, VP of Product Strategy at Salt Security

Salt Security created the API security category and built the OWASP API Top 10. The platform gives security teams one inventory of APIs and MCP servers across cloud and on-premise environments, with visibility, governance, and threat protection for AI agents deployed as critical infrastructure.

Run a free external attack surface assessment: https://salt.security/attack-surface

Timestamps:

0:00 Third webinar on securing agentic AI

1:45 The AI revolution and the API security problem

4:35 AI agents, LLMs, and MCP servers defined

6:24 Before and after: how MCP transforms your architecture

8:30 The API fabric and its sharp expansion

9:37 Three buckets of risk: attack surface, data leakage, new attacks

11:44 Five questions to ask about your AI agents

13:50 Mapping the AI security landscape

16:32 The agentic AI life cycle, from model to action

20:42 Model security versus the agentic action layer

24:56 The Chevy dealership $1 car prompt injection

27:27 Agentic General Hospital: unintended actions and attack surface

31:56 Shadow MCP servers and internal exposure

33:51 How Salt secures the agentic action layer

36:00 Product demo: bringing the API fabric to life

38:20 AI policy compliance and building your own policies

40:57 Behavioral threat protection for MCP traffic

42:33 Why agents as critical infrastructure carry the real risk

44:44 Q&A: context management, on-prem, SIEM, and local MCP servers

55:28 Analyst perspectives and free resources