mcp
4 posts.
- MCP Attacks on Xata and GitHub MCP: Read-Only Bypass and Issue InjectionDay 8 / 100 · AI cybersecurity
A first-person walkthrough of two MCP attack labs: a Xata-style read-only SQL bypass and a GitHub public-issue injection that exposed the difference between model safety and application security.
- The MCP confused deputy problemDay 6 / 100 · AI cybersecurity
A hands-on MCP lab showed how a valid tenant key can still retrieve another tenant's project when the server never checks resource ownership.
- MCP security labs: path bypasses and poisoned tool responsesDay 7 / 100 · AI cybersecurity
Two MCP labs showed different failures at the same boundary: a filesystem server trusted a string prefix, while a facts server poisoned the agent's next tool call.
- MCP security: when prompt injection gets a toolDay 5 / 100 · AI cybersecurity
MCP makes it easier for AI systems to use external tools. It also connects model behaviour to permissions, private data, and real actions.







