Security Considerations

Modified on Wed, 26 Aug at 6:25 PM

When using an AI tool (or MCP client) to interact with Projectal, it is strongly recommended to use AI tools that you trust. 


Once an AI tool has connected to your Projectal, then it can access the same data and do the same actions that you can with your user account in Projectal.


Before installing an AI tool or MCP client onto your computer, verify the tool is legitimate and has high trust ratings.


Guard Against Prompt Injection 


Prompt injection occurs when untrusted content contains instructions that try to change an AI tool or MCP client’s behavior.  Learn more here.


An attacker could put a malicious instruction in content that your AI tool or MCP client reads. If the client follows the instruction, it could disclose data or change content without your intent. So you must treat content returned by tools as untrusted. Review proposed actions and data sharing before approving them. 


Review the permissions of every AI tool and MCP client that you use. The Projectal MCP server operates using your Projectal user account, but a connected AI tool or MCP client could send content returned by Projectal MCP server to external systems. 

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article