Depending on the setup, you just have to be really careful to avoid confused deputy scenarios.
I wrote about it: https://den.dev/blog/mcp-confused-deputy-api-management/