惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
T
Threatpost
T
Tor Project blog
S
Schneier on Security
Project Zero
Project Zero
Know Your Adversary
Know Your Adversary
P
Proofpoint News Feed
K
Kaspersky official blog
P
Privacy International News Feed
Latest news
Latest news
Cisco Talos Blog
Cisco Talos Blog
T
The Exploit Database - CXSecurity.com
The Hacker News
The Hacker News
D
Docker
aimingoo的专栏
aimingoo的专栏
S
Securelist
C
Cyber Attacks, Cyber Crime and Cyber Security
Spread Privacy
Spread Privacy
TaoSecurity Blog
TaoSecurity Blog
T
The Blog of Author Tim Ferriss
T
Threat Research - Cisco Blogs
Simon Willison's Weblog
Simon Willison's Weblog
博客园 - 三生石上(FineUI控件)
人人都是产品经理
人人都是产品经理
Security Latest
Security Latest
V
Visual Studio Blog
WordPress大学
WordPress大学
J
Java Code Geeks
O
OpenAI News
T
Tailwind CSS Blog
S
Secure Thoughts
G
Google Developers Blog
博客园_首页
The Cloudflare Blog
The Register - Security
The Register - Security
A
Arctic Wolf
Y
Y Combinator Blog
阮一峰的网络日志
阮一峰的网络日志
B
Blog RSS Feed
IT之家
IT之家
美团技术团队
D
Darknet – Hacking Tools, Hacker News & Cyber Security
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
G
GRAHAM CLULEY
S
Security Affairs
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Application and Cybersecurity Blog
Application and Cybersecurity Blog
P
Palo Alto Networks Blog
C
CERT Recently Published Vulnerability Notes
W
WeLiveSecurity

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
I Scanned 1,200 MCP Configs From GitHub. Here's What I Found.
AD · 2026-06-26 · via DEV Community

A deep-dive into the security posture of real-world AI agent deployments — and the open-source tool I built to fix it.


TL;DR

I collected 1,200 real MCP (Model Context Protocol) configuration files from public GitHub repositories, scanned them with an open-source security tool I built, and found that:

  • 100% had security gaps
  • 20.7% had CRITICAL or HIGH issues (hardcoded secrets, unauthenticated endpoints, unrestricted shell execution)
  • 0 of 1,200 configured response limits or session caps
  • The 11 most popular MCP servers (307K+ combined stars) all had findings — 5 were CRITICAL

The tool is Pluto AgentGuard. It's free, runs locally, and takes about 3 minutes to scan 1,200 configs.


The Problem: We Secured LLM Outputs but Forgot About Agent Actions

The AI security conversation has focused heavily on what LLMs say — hallucinations, jailbreaks, harmful content. Entire product categories exist for prompt filtering and output guardrails.

But the attack surface has shifted. Modern AI agents don't just generate text — they do things: browse the web, execute shell commands, query databases, push code, trigger CI/CD pipelines. The Model Context Protocol (MCP) is the dominant standard for connecting these capabilities to LLMs.

Here's the disconnect: nobody is auditing the configuration layer that determines what agents can actually do. The MCP config file — usually claude_desktop_config.json or .mcp.json — is the security boundary between "an AI assistant that helps me code" and "an AI assistant that can run arbitrary commands on my machine."

I wanted to know: how secure are these configurations in the real world?


Methodology: How I Collected 1,200 Configs

Collection

I used the GitHub Code Search API to find real MCP configuration files across public repositories. The search targeted:

  • claude_desktop_config.json files containing mcpServers
  • .mcp.json files with MCP server definitions
  • mcp_config.json and similar variants

Collection rules:

  • Maximum 3 configs per repository (avoid bias from monorepos)
  • Deduplicated by SHA-256 content hash (identical configs counted once)
  • Only files that parsed as valid JSON with MCP server definitions
  • 7-second delay between API pages (GitHub rate limit: 10 requests/minute)

Result: 1,200 valid configs from 1,159 unique repositories, collected June 25, 2026.

Scanning

Each config was scanned using Pluto AgentGuard's scan_mcp_config function, which checks for:

  1. Dangerous server packages — a curated database of 13+ MCP servers known to grant high-risk capabilities (shell execution, browser control, database write, source control write)
  2. Missing authentication — remote MCP endpoints (http:// or https:// URLs) without auth headers or tokens
  3. Insecure transport — HTTP instead of HTTPS for remote connections
  4. Hardcoded secrets — 18+ regex patterns matching API keys, tokens, passwords, and private keys embedded in config values
  5. Context safety gaps — missing response size limits (max_tokens, max_response_length) and session caps (max_turns, session_timeout)
  6. Human-in-the-loop (HITL) absence — high-risk servers configured without approval gates

Each finding is assigned a severity (CRITICAL / HIGH / MEDIUM / LOW / INFO) and mapped to OWASP Agentic AI threat categories.

The entire scan ran locally in ~3 minutes. No API keys. No cloud. No LLM calls.


Results: The Numbers

Overall (1,200 configs)

Metric Value
Total configs scanned 1,200
Unique repositories 1,159
Total findings 2,904
🔴 CRITICAL 88 (3.0%)
🟠 HIGH 280 (9.6%)
🟡 MEDIUM 2,536 (87.3%)
Configs with CRITICAL or HIGH 20.7%
Configs with any finding 100%

Every single config had at least a MEDIUM finding. One in five had a CRITICAL or HIGH issue.

The Popular Servers (11 configs, 307K+ combined GitHub stars)

I also separately scanned the 11 highest-starred MCP servers to see how the most popular, most copied configs look:

Server Stars Max Severity Key Finding
Context7 58K 🔴 CRITICAL No authentication on remote endpoint
Chrome DevTools MCP 44K 🔴 CRITICAL Full Chrome DevTools Protocol access, no HITL
Playwright MCP 34K 🟠 HIGH Full browser automation, no HITL
GitHub MCP 31K 🟠 HIGH Can merge PRs + trigger CI/CD, no HITL
Serena 26K 🔴 CRITICAL Unrestricted shell execution, no HITL
FastMCP 26K 🟡 MEDIUM Context safety gaps
Activepieces 23K 🔴 CRITICAL No authentication on remote endpoint
n8n MCP 22K 🟠 HIGH Arbitrary code execution via workflows, no HITL
Google MCP Toolbox 16K 🟠 HIGH Unrestricted SQL (supports 20+ databases), no HITL
Figma MCP 15K 🟡 MEDIUM External content injection risk
mcp-chrome 12K 🔴 CRITICAL No auth + insecure HTTP transport

5 CRITICAL. 4 HIGH. 0 of 11 had response limits or session caps.

I've filed security issues on the CRITICAL repos: Context7, Chrome DevTools, Serena, Activepieces, mcp-chrome.


The 4 Most Common Risks (With Examples)

1. Browser Control Without Approval (CRITICAL)

Chrome DevTools MCP (44K★) gives the agent full Chrome DevTools Protocol access. That means:

✅ Attach to your existing Chrome sessions
✅ Execute JavaScript in page context
✅ Capture network response bodies (credentials, tokens, PII)
✅ Read cookies and local storage
✅ Intercept and modify requests

A prompt injection — say, a malicious instruction hidden in a webpage the agent is reading — can instruct the agent to exfiltrate your session cookies from Gmail, your bank, or your corporate SSO.

The default config has zero approval gates. The agent acts autonomously.

2. Shell Execution Without Sandboxing (CRITICAL)

Serena (26K★) gives the agent unrestricted shell access. Not "run this safe command" — full bash with the agent's user permissions. Combined with filesystem read/write, a prompt injection can:

  • Read ~/.ssh/id_rsa and exfiltrate it
  • Install a reverse shell
  • Modify .bashrc for persistence
  • Access cloud credentials in ~/.aws/credentials

3. Unauthenticated Remote Endpoints (CRITICAL)

Context7 (58K★) and Activepieces (23K★) expose remote MCP endpoints over HTTPS with no authentication. Anyone who knows the URL can connect.

The typical config looks like:

{
  "mcpServers": {
    "context7": {
      "url": "https://mcp.context7.com/mcp"
    }
  }
}

No API key. No OAuth. No mTLS. The equivalent of deploying a REST API with no auth and hoping nobody finds it.

4. Missing Response Limits (MEDIUM — but universal)

Zero of 1,200 configs set max_response_length or max_tokens on their MCP servers. This enables context stuffing attacks: a malicious tool returns an oversized response that pushes the agent's system prompt and safety instructions out of the context window.

This is the lowest-effort fix imaginable — add two lines to your config — and nobody does it.


Why This Matters: The "Left of Boom" Gap

The current AI security stack looks like this:

[Prompt Filters] → [LLM] → [Output Guardrails] → [Agent Actions]
     ✅ covered         ✅ covered            ❌ unmonitored

Teams invest in prompt injection detection and output filtering. But the agent action layer — what the LLM actually does through MCP tools — is a blind spot. There's no "firewall" between the LLM's tool-use decision and the actual execution.

This is the "left of boom" problem. By the time an output guardrail catches something, the agent has already:

  • Executed the shell command
  • Queried the database
  • Merged the pull request
  • Browsed your authenticated session

You need to catch the risk before the agent gets access to these capabilities. That means auditing the configuration layer.


Introducing Pluto AgentGuard

I built Pluto AgentGuard to fill this gap. It's a security launch gate for AI agents — you run it before deploying, not after something breaks.

What it does (7 commands)

Command What it does
aguard scan Static analysis of MCP configs, secrets, permissions
aguard test 22 attack scenarios across 6 packs test your policy's coverage
aguard whatif Simulate policy changes and see risk delta before applying
aguard owasp Map findings to 20 OWASP-inspired controls
aguard evidence Generate launch readiness evidence packets
aguard baseline Create baselines, detect configuration drift over time
aguard monitor Replay agent traces, detect unauthorized tool calls

Quick start

pip install pluto-aguard

# Scan your MCP config
aguard scan ./your-project/

# Test your policy against attack scenarios
aguard test --policy ./policy.yaml --attack-pack all

# See what happens if you add a new server
aguard whatif --config ./config.yaml

# Map to OWASP controls
aguard owasp ./your-project/

What makes it different

Most MCP security tools do config scanning. AgentGuard adds three things I haven't seen elsewhere:

  1. Policy testing (aguard test): Instead of "does your config have issues?", it asks "does your policy actually stop attacks?" — 22 scenarios covering prompt injection, data exfiltration, privilege escalation, context manipulation, supply chain, and social engineering.

  2. What-if simulation (aguard whatif): Before you add a new MCP server or change a policy rule, simulate the impact. See the risk score delta. Catch regressions before they ship.

  3. Evidence generation (aguard evidence): Produces a structured evidence packet (scan results + test results + OWASP mapping + risk score) for security review sign-off. Useful for enterprise teams that need launch gates with artifacts.

CI/CD integration

AgentGuard ships as a GitHub Action:

- uses: arpitha-dhanapathi/pluto-aguard@v0.9.2
  with:
    scan-path: ./
    fail-on: high  # Block PR if HIGH or CRITICAL found
    format: sarif   # Upload to GitHub Security tab

It also supports JSON, Markdown, HTML, and SARIF output formats.


What You Should Do Right Now

If you're using MCP servers in any AI agent setup, here's a 5-minute security checklist:

1. Run a scan (30 seconds)

pip install pluto-aguard
aguard scan ./your-project/

2. Add response limits (1 minute)

Add to every MCP server in your config:

{
  "max_response_length": 8000,
  "max_turns": 20,
  "session_timeout": 3600
}

3. Add HITL for dangerous servers (2 minutes)

If you use Chrome DevTools, Playwright, Serena, filesystem, or any shell-capable server — enable human-in-the-loop approval. The exact mechanism depends on your client (Claude Desktop, Cursor, VS Code, etc.), but the principle is: the agent should ask before executing destructive operations.

4. Authenticate remote endpoints (2 minutes)

If your MCP server is remote (HTTPS URL instead of stdio), add auth:

{
  "mcpServers": {
    "my-server": {
      "url": "https://my-server.com/mcp",
      "headers": {
        "Authorization": "Bearer ${MCP_API_KEY}"
      }
    }
  }
}

5. Add AgentGuard to your CI (bonus)

Block PRs that introduce MCP misconfigurations:

- uses: arpitha-dhanapathi/pluto-aguard@v0.9.2
  with:
    scan-path: ./
    fail-on: high


The Bigger Picture

MCP is 18 months old and already the de facto standard for agent-to-tool communication. The ecosystem is moving fast — 90K+ stars on awesome-mcp-servers, thousands of servers, and major platforms (Claude, Cursor, VS Code, Windsurf) supporting it natively.

But the security tooling hasn't kept pace. We're in the "move fast and break things" phase of agent infrastructure, and the configs people are shipping to production look like the web in 2005 — no auth, no limits, full trust.

The good news: the fixes are simple. Auth headers, response limits, HITL approval, and a scan in CI. None of this requires new technology — just applying existing security principles to a new surface.

The bad news: right now, almost nobody is doing it.

Let's fix that.


Pluto AgentGuard is open-source (Apache 2.0), written in Python, and runs entirely locally. Star it on GitHub if this was useful.

Have questions or findings to share? Open an issue or find me on LinkedIn.


Tags: #security #ai #opensource #python #mcp #agents