Threat-model and secure MCP Apps, MCP servers, and custom hosts. Review iframe isolation, postMessage validation, tool authorization, Streamable HTTP Origin checks, session safety, OAuth, SSRF, XSS, prompt injection, secrets, and untrusted MCP content. WHEN: 'secure my MCP App', 'MCP App threat model', 'review MCP host security', 'is this iframe sandbox safe', 'prevent SSRF', 'secure MCP OAuth', 'validate postMessage', 'security audit MCP server'.