Policy dependency / Threat pattern
mcp-shell Ships Security Off in One Deploy Path and Bypassable in the Other (CVE-2026-55580/55581/55582)
GitHub Security Advisories
Policy dependency / Stack layer
Attnlocate treats prompt injection as an object detection problem inside the attention matrix, hitting 0.934 TPR at 0.067 FPR
arXiv
Policy dependency / Stack layer
WebMCP-Phalanx blocks all 80 tool-description injections in a browser agent, then gets bypassed by a malicious tool name called before inspection
arXiv
Stack layer / Contrast
Anthropic's own weekly sales digest runs on Claude Code plus a BigQuery MCP connector and nine hand-written content rules
Claude by Anthropic
Stack layer / Threat pattern
TrustShiftProbe: a compromised MCP server that behaves for N calls then defects hits 69.5% attack success, and the best defense only halves it
arXiv
Policy dependency / Stack layer
A flow-centric policy language cut confirmed agent compromise from 33% to 0% on AgentDojo while raising utility
arXiv 2608.22868
Policy dependency / Stack layer
Halofy ships an open governance layer for agents with identity, policy, provenance, audit and signed erasure
GitHub
Policy dependency / Stack layer
SMITH Trains Tool Creation and Tool Use in One Policy; a 4B Qwen3 Beats an Untrained 30B Tool-Writer at 79.8 Macro Accuracy
arXiv 2608.24571