agent-security
2 posts.
- MCP Attacks on Xata and GitHub MCP: Read-Only Bypass and Issue InjectionDay 8 / 100 · AI cybersecurity
A first-person walkthrough of two MCP attack labs: a Xata-style read-only SQL bypass and a GitHub public-issue injection that exposed the difference between model safety and application security.
- MCP security: when prompt injection gets a toolDay 5 / 100 · AI cybersecurity
MCP makes it easier for AI systems to use external tools. It also connects model behaviour to permissions, private data, and real actions.



