Security research focused on Model Context Protocol (MCP) implementations and AI-assisted development tools.
Live Site: mcpsec.dev
This site publishes security advisories and research findings related to:
- AI agents and coding assistants
- Model Context Protocol (MCP) servers and implementations
- Prompt injection vulnerabilities
- Supply chain attacks in AI tooling
- Authentication and authorization issues in AI development tools
- Kilo Code AI Agent Supply Chain Attack
- Coder Chat Exfiltration
- thirdweb MCP Unauthorized Transactions
- Grafana MCP Unauthenticated SSE Access
Subscribe to security advisories via RSS:
- RSS Feed: mcpsec.dev/rss
- Atom Feed: mcpsec.dev/feed.xml
Evan Harris
- X: @Evan__Harris
- GitHub: eharris128
For instructions on running this site locally or contributing, see DEVELOPMENT.md.