What happened
At Dreamforce (announced Sept 22, 2026 via the Dreamforce IT announcements blog), Salesforce shipped MCP Security & Risk Scores in Agentforce: on MCP server registration, the system automatically scans for prompt injections, tool poisoning, and 'rug pull' attacks and outputs a Low/Medium/High risk rating with remediation steps before any connection is authorized, then continuously re-scans to flag malicious post-registration changes.
Why it matters
MCP server risk is one of the most active agent-attack surfaces of the current cycle, and this puts automated, pre-connection supply-chain scanning for agents directly into a top enterprise platform's first-party agent product — mainstreaming MCP security rather than leaving it to bolt-on agents. It is a signal that MCP/agent-tool exposure will be treated as a first-class, continuously-verified control in enterprise CRM/agent estates.
Applicability
Salesforce admins and CISO teams deploying Agentforce agents should enable MCP registration risk scoring before connecting third-party MCP servers; enterprises evaluating agent-securing controls should benchmark this against dedicated MCP-security vendors.