独立したセキュリティ研究
AI・エージェント・MCP サーバーのセキュリティ研究
Model Context Protocol(MCP)の実装や AI 支援型の開発ツールに存在する脆弱性を発見し、責任ある開示を行ったうえで、メンテナーやサイト運営者の方々と協力して修正につなげています。
最近のアドバイザリー
-
Vet MCP Server SSE Transport DNS Rebinding Vulnerability
-
Amp AI Agent Allows API Key Exfiltration Via Prompt Injection
-
Kilo Code AI Agent Exposes Users to Supply Chain Attack Via Prompt Injection
-
Coder's Agent API Exposes User Chat History Via DNS Rebinding Attack
-
Unauthorized Crypto Transactions Enabled by thirdweb MCP Server
-
Grafana MCP Server Exposes Unauthenticated SSE Interface Enabling Remote Dashboard Manipulation