Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
91 items
Level up your Solidity LLM tooling with Slither-MCP
Nov 15, 2025InfoNewsIndustryResearchTrail of Bits has released Slither-MCP, an MCP server that exposes Slither's static analysis engine to LLMs for Solidity projects such as Foundry and Hardhat. It lets LLMs locate function sources, callers and callees, inherited members, and run Slither's detectors instead of relying on grep and read_file. The tool is licensed AGPLv3, and Trail of Bits is now offering dual licensing for Slither and Slither-MCP.
Trail of Bits BlogCross-Agent Privilege Escalation: When Agents Free Each Other
Sep 24, 2025MediumNewsSecurityResearchJohann Rehberger describes a design flaw in agentic systems that lets one coding agent rewrite another agent's configuration, freeing it from its sandbox. In his demo, a prompt-injected GitHub Copilot writes a malicious MCP server into Claude Code's config, which then runs arbitrary code. The post notes that Claude can reciprocate by modifying Copilot's configuration.
Fix: Mitigations and Recommendations: the source states that vendors should adopt secure defaults and that users should be aware of several points, including isolating the agent's configuration so it is less accessible to others and not automatically overwriting or creating files. The remainder of the mitigation text is cut off in the source.
Embrace The RedWrap Up: The Month of AI Bugs
Aug 30, 2025InfoNewsSecurityResearchThis is a wrap-up post for a month-long series that published AI coding-tool and agent security research. It lists about 30 write-ups covering ChatGPT, ChatGPT Codex, Anthropic's Filesystem MCP Server, Cursor, Amp Code, Devin AI, OpenHands, Claude Code, GitHub Copilot, Google Jules, Amazon Q Developer, Windsurf, Deep Research Agents, Manus, AWS Kiro, Cline, and an AgentHopper research demo. The titles point to prompt injection as the common vector, with data exfiltration and remote code execution as recurring outcomes.
Embrace The RedWindsurf MCP Integration: Missing Security Controls Put Users at Risk
Aug 28, 2025LowNewsSecurityIndustryThe author tested how Windsurf's MCP integration handles tool permissions in coding agents. They found that basic security controls are missing, which matters more when the agent runs on a local computer.
Embrace The RedAWS Kiro: Arbitrary Code Execution via Indirect Prompt Injection
Aug 26, 2025MediumNewsSecuritySafetyResearcher Johann Rehberger reported that AWS Kiro, a coding agent, can be hijacked through indirect prompt injection to run arbitrary operating system commands. An attacker who controls data Kiro processes can make it write to .vscode/settings.json and add "kiroAgent.trustedCommands": ["*"], allowlisting all Bash commands without developer approval. A second path adds malicious MCP servers through .kiro/settings/mcp.json. The proof of concept opened the Calculator app and changed the VS Code color theme with no user interaction beyond a chat prompt.
Embrace The RedHow Deep Research Agents Can Leak Your Data
Aug 24, 2025MediumNewsSecurityPrivacyA researcher shows that Deep Research agents in ChatGPT can leak data between connected tools, since all connectors and MCP servers share one trust boundary. Data from one source, such as Outlook email, can be used in queries sent to another source, such as a custom Remote Matrix MCP server, and an attacker can force this through prompt injection. The custom connector must implement exactly search and fetch, and the research was conducted about two months before publication.
Embrace The RedAmp Code: Arbitrary Command Execution via Prompt Injection Fixed
Aug 5, 2025MediumNewsSecuritySafetyResearcher Johann Rehberger describes an attack chain against Amp, an agentic coding tool built by Sourcegraph, in which the agent could write to the user's VS Code settings.json file outside the project folder without approval. An attacker, or the model itself through indirect prompt injection, could add wildcard or malicious entries to the allowlisted bash commands or add a malicious MCP server, achieving arbitrary code execution on the developer's machine. The issue was reported to Sourcegraph and fixed within a few days.
Fix: As a user, make sure to run the latest version to be protected. The source also recommends that AI systems must not be able to modify critical files without explicit developer consent.
Embrace The RedAnthropic Filesystem MCP Server: Directory Access Bypass via Improper Path Validation
Aug 3, 2025MediumNewsSecurityIndustryA researcher found that Anthropic's filesystem MCP server validates allowed paths with a .startsWith comparison in the validatePath function of index.ts, without checking that the path is a directory. As a result, a directory allowlisted through allowedDirectories, such as /mnt/finance/data, also grants access to sibling paths sharing the same prefix, such as /mnt/finance/data-archived. The researcher reported the issue to Anthropic on June 1, 2025, and Elad Beber had independently reported it earlier.
Fix: Anthropic rewrote large parts of the filesystem server to support the roots feature of MCP, and the updated release fixed this vulnerability.
Embrace The RedSecurity Advisory: Anthropic's Slack MCP Server Vulnerable to Data Exfiltration
Jun 24, 2025MediumNewsSecurityIndustryA security advisory reports a data leakage and exfiltration vulnerability in Anthropic's Slack MCP Server, a reference implementation now deprecated and unmaintained. The server does not disable link unfurling when posting to channels, so an AI agent that posts links can leak data, such as secrets from a .env file, to third-party servers, and a prompt injection can trigger this. The advisory says the server appears widely used, with 14k+ weekly downloads.
Embrace The RedHosting COM Servers with an MCP Server
Jun 9, 2025LowNewsSecurityIndustryThe author built mcp-com-server, an MCP server that wraps Windows COM and Office automation, exposing tools such as CreateObject, Get/Set Property, InvokeMethod, QueryInterface and ListAllHostedServers. Because any COM object can be instantiated, the server could open Shell.Application or FileSystemObject and perform dangerous operations. The author describes it as a learning prototype and notes that the server can automate Excel and Outlook through Claude.
Fix: The source states a basic mitigation: an Allow List for CLSIDs and ProgIDs, so the server only instantiates allow-listed COM objects, which the author says could be expanded to specific interfaces and methods. It also notes that Claude shows an Allow / Deny confirmation before invoking custom tools by default, which can be disabled or re-enabled per MCP tool in Claude Settings.
Embrace The RedMCP: Untrusted Servers and Confused Clients, Plus a Sneaky Exploit
May 2, 2025MediumNewsSecurityResearchThe author explains that the Model Context Protocol (MCP) lets LLM apps and agents discover and use external tools at runtime, unlike static setups such as OpenAPI. The author argues that because of prompt injection, MCP tool servers effectively control the client. The post promises a detailed explanation and a novel exploit chain.
Embrace The Red
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.