I think that’s exactly right: MCP provides a capability security model for agents.