Blog
MCP security research, AI agent infrastructure, and practical guides.
-
Vibe Coding and MCP Security: What Every AI Developer Needs to Know
Vibe coding with Claude Code, Cursor, or Windsurf? Every MCP server you add runs with your full permissions. Here's the threat model, real attack vectors, and how to protect yourself.
-
Claude Code + MCP: Security Risks Every Developer Should Know
Every MCP server you add to Claude Code runs locally with your permissions and gets direct write access to Claude's context. Here are the four attack surfaces and how to stay safe.
-
MCP Tool Poisoning: How Malicious Servers Hijack Your AI Agent
Hidden instructions in MCP tool descriptions can override your AI agent's behavior without you knowing. How tool poisoning works, real examples, and how to stop it.
-
State of MCP Security: Q2 2026
A data-driven report on MCP server security in Q2 2026. Scan results from 50 servers, common vulnerabilities, ecosystem trends, and what needs to change.
-
The EU AI Act and MCP: What Changes in August 2026
The EU AI Act's general-purpose AI provisions take effect August 2, 2026. What that means for MCP server developers and companies deploying AI agents.
-
MCP Security FAQ: Common Questions About MCP Server Safety
Answers to the most common questions about MCP server security. What is MCP, how to audit servers, what permissions mean, and how to stay safe.
-
I Scanned 50 Popular MCP Servers. Here's What I Found.
Real audit data from the 50 most-starred MCP servers on GitHub. Average score: 90.5. One critical eval() finding. 43 of 50 had no analyzable JS/TS source code.
-
MCP Security Checklist: 15 Things to Check Before Deploying
A 15-point security checklist for MCP servers. Covers permissions, code safety, supply chain, transparency, and deployment.
-
MCP Permissions Explained: What Servers Can Actually Do
A plain-language guide to MCP server permissions. What filesystem, network, shell, and environment access actually means, and why the protocol does not enforce boundaries.
-
Why You Should Audit MCP Servers (Even the Popular Ones)
Star count is not a security guarantee. Google's CLI scored in the bottom five. A 7,000-star server had eval(). Why auditing matters.
-
How to Audit Your MCP Servers Before Installing
A practical guide to auditing MCP servers before you install them. Check permissions, code safety, supply chain risk, and more in under two minutes.
-
Getting Started with MCP Audit: Your First Server Scan
Step-by-step tutorial for running your first MCP server audit. Paste a URL, read the report, understand the scores. Takes about 90 seconds.
-
MCP vs CLI for Agent Tool Integration: When to Use Which
Comparing MCP servers and CLI tools for connecting AI agents to external tools. Structured protocol vs shell commands: trade-offs, security, and practical advice.
-
Building a Newsletter for AI Agents, Not Humans
A newsletter pipeline where AI agents are the primary readers. Structured data, machine-parseable format, and a surprise generator.
-
How One Claude Code Session Built an Entire Newsletter Pipeline
How one Claude Code session built a full newsletter pipeline for AI agents: 8-stage architecture with aggregation, vetting, scoring, and humanization.
Get the Agent Upgrade Feed
Weekly tools, techniques, and integrations for AI agents. Security-vetted, no fluff.
Subscribe Free