Secure AI Agent with RAG & MCP
Dexfense ReviewedReference architecture for an AI assistant using document retrieval, agent memory, MCP tool connectors and external APIs.
Overview
Covers an internet-facing AI agent powered by a foundation model, augmented with retrieval-augmented generation over a document corpus, agent memory for context persistence, and MCP servers for external tool access. Suitable for enterprise copilots, research assistants and automated customer-facing agents. Security coverage spans prompt injection, memory poisoning, tool abuse, data exfiltration and supply-chain risks mapped to MITRE ATLAS and OWASP LLM Top 10.
Intended for
Security architects and developers building AI-native applications, enterprise copilots and autonomous agent systems.
Architecture Assumptions
This template assumes the following conditions. If your environment differs, use Remix to adapt the component selection.
- The agent is internet-facing and accepts user-controlled prompts
- Users authenticate via an identity provider using OAuth 2.0
- The vector store holds documents that may contain sensitive information
- The agent connects to external APIs and tools via MCP
- LLM API calls are routed through an API gateway that holds provider keys
Out of Scope
- LLM provider-specific safety controls (e.g. OpenAI moderation layers) are not assessed
- Agent runtime code quality and injection hygiene are not reviewed at code level
- Assumes single-tenant deployment; multi-tenant isolation is not modelled
- No active scanning of connected MCP tools or external APIs
Architecture Components10 components selected
AI Agents & LLM
LLM / Foundation Model
Large language model or foundation model powering agent reasoning
Agent Orchestrator
Framework or runtime that coordinates agent tasks and tool calls
Agent Memory
Short-term and long-term memory stores used by the agent
MCP Servers
Model Context Protocol servers exposing tools and resources to agents
RAG / Knowledge Base
Retrieval-augmented generation system and associated knowledge stores
LLM API Gateway
API layer routing requests to LLM providers — holds API keys and rate limits
Web & APIs
API Services
API endpoints for application integration
Databases
NoSQL Databases
Non-relational databases for unstructured data
Auth & IAM
OAuth/OIDC
Open authorization and identity protocols
Monitoring
Logging Systems
Centralized log collection and management
Security Preview
Based on this architecture's component selection
Indicative Risk Score
50/100
15 techniques identified
5 Critical · 0 High
Top Attack Techniques
- CriticalAIA-001Prompt Injection
- CriticalAIA-002Indirect Prompt Injection
- CriticalAIA-004Memory Poisoning
- CriticalAIA-007Tool Abuse
- CriticalAIA-008MCP Server Compromise
Top Recommended Controls
- 1Implement Web Application Firewall (WAF) and regular security testing
- 2Focus on Attack Surface Reduction as your highest priority security initiative
The full defense plan — mitigations, detection methods, NIST CSF 2.0 mapping and exportable report — is available when you use this architecture in the planner.
Remix copies the components so you can add or remove items before generating your assessment.
Dexfense does not scan your systems. This template identifies threats and controls relevant to this architecture. Product and version validation is still required.