Independent security research
Security research on AI, agents, and MCP servers
I find and responsibly disclose vulnerabilities in Model Context Protocol (MCP) implementations and AI-assisted developer tools, then work with maintainers and site operators to get them fixed.
For website operators
Received a security notice from me?
Verify it is genuine and find the guidance page for the component named in the email. I am not asking for money, passwords, or access to your site.
Check your notice →Already updated? One more step.
Updating closes the hole from now on. It cannot tell you whether anyone found it first. A practical 30-minute self-check, no security background needed.
I updated. Now what? →Found something in the self-check you are not sure about? Reply to the notice email. I read every reply.
Recent advisories
-
Vet MCP Server SSE Transport DNS Rebinding Vulnerability
-
Amp AI Agent Allows API Key Exfiltration Via Prompt Injection
-
Kilo Code AI Agent Exposes Users to Supply Chain Attack Via Prompt Injection
-
Coder's Agent API Exposes User Chat History Via DNS Rebinding Attack
-
Unauthorized Crypto Transactions Enabled by thirdweb MCP Server
-
Grafana MCP Server Exposes Unauthenticated SSE Interface Enabling Remote Dashboard Manipulation