The rapid adoption of the Model Context Protocol (MCP) has enabled powerful AI agents to access external systems and corporate data via defined tools. However, this accelerated growth has created a dangerous security gap. This article dissects the leading attack vectors targeting MCP-powered agents, specifically the Prompt Injection and Supply Chain Attack (Rugpull) exploits and outlines actionable, technical mitigation strategies.