The OWASP MCP Top 10 identifies critical vulnerabilities in AI agent systems using the Model Context Protocol. Most of these risks, such as token exposure, privilege escalation, prompt injection, and insufficient authorization, stem from the same root cause: traditional IAM was built for humans, not agents.