MCP Security Research is the independent security research of Evan Harris. The focus is the Model Context Protocol (MCP) and the fast-growing ecosystem of AI agents and AI-assisted development tools, software that is being adopted quickly and often ships with weak authentication, unsafe defaults, and exposed network interfaces.

The work here is straightforward: find real vulnerabilities, report them responsibly to the people who can fix them, and publish clear write-ups once fixes are available so the wider community can learn from them.

What this research covers

  • MCP server and transport security, including unauthenticated SSE interfaces, DNS rebinding, and missing origin validation.
  • AI agent security, including prompt injection, supply-chain risks, and unsafe tool execution.
  • Vulnerabilities in AI and ML tooling, including deserialization and remote code execution in machine-learning platforms.

Every finding is documented in the security advisories, with affected versions, impact, and remediation guidance. Recent work includes disclosures affecting MLflow, AWS Labs’ Amazon MQ MCP server, Grafana’s MCP server, and Neo4j, among others.

If I contacted you

Some of this research involves notifying operators of internet-facing software that is running a vulnerable or end-of-life component. If you received an email from me, it was a good-faith, responsible-disclosure notice. To be clear about what that means:

  • I only read public information your site already serves to every visitor, such as a published version manifest.
  • I did not attempt to break into your site, exploit anything, or access any private data.
  • I will never ask you for money, passwords, or access to your systems.

If you are here after receiving a notice, the For Site Operators page explains what to check and how to fix it. My full process is described in the disclosure policy.

Verify this is really me

You are right to be cautious about unsolicited security messages. You can cross-check that any message claiming to be from me lines up with these public profiles:

Report a vulnerability

If you have found a security issue in a project I maintain, or want to reach me about coordinated disclosure, email security@mail.mcpsec.dev. See the disclosure policy for details on scope and timelines.