Review MCP server risk from exposed tools, prompt boundary, auth model, data access, and change history