AI agents use MCP servers to call tools that can reach real data. This session will walk through one attack chain that makes an agent leak sensitive information, then show how three controls deny-by-default egress, request guards, and DLP canaries stop it. Attendees will take home a small open harness, a hardening checklist, and policies they can deploy quickly.