Wasm't That Easy - Securing MCP With Wasm Sandboxes
CNCF [Cloud Native Computing Foundation] via YouTube
Overview
Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Explore how WebAssembly (Wasm) Component Model provides a secure solution for running third-party Model Context Protocol (MCP) servers in this 24-minute conference talk from CNCF. Learn to replace insecure runtimes and heavy containers with lightweight, sandboxed binaries that feature deny-by-default permissions and fine-grained access control. Discover practical approaches to preventing unwanted file access and blocking calls to untrusted domains while maintaining functionality. Watch live demonstrations showing how to pull tools from OCI registries, restrict system resource access, and prevent real-time data exfiltration attacks. Understand the security risks associated with untrusted code in AI supply chains and see how Wasm sandboxes can mitigate threats from malicious tools attempting to steal sensitive data. Gain insights into building a more secure AI ecosystem by implementing explicit, auditable policies for third-party tool access and creating safer environments for AI agents.
Syllabus
Wasm't That Easy: Securing MCP With Wasm Sandboxes - Jiaxiao Zhou, Microsoft & Taylor Thomas, Akuity
Taught by
CNCF [Cloud Native Computing Foundation]