Policy dependency / Stack layer
mcp-shell Ships Security Off in One Deploy Path and Bypassable in the Other (CVE-2026-55580/55581/55582)
GitHub Security Advisories
Stack layer / Threat pattern
PraisonAI Validated MCP Origins With startswith, So localhost.attacker.com Passed the Allowlist
GitHub Security Advisories
Policy dependency / Stack layer
MCP-Universe RL trains tool-use agents by using MCP servers as the RL environment interface
arXiv
Stack layer / Threat pattern
48 threats catalogued against Google's Agent Payments Protocol v0.2, eight of them High severity, because signed mandates do not cover the pre-authorization context
arXiv
Policy dependency / Stack layer
Agno 3.0.1 caches tool schemas across runs and loads session history incrementally, so response time stops scaling with conversation length
GitHub (agno-agi/agno)
Stack layer / Threat pattern
TrustShiftProbe: a compromised MCP server that behaves for N calls then defects hits 69.5% attack success, and the best defense only halves it
arXiv
Policy dependency / Stack layer
A vision paper separates access from control and argues AI concentrates software power rather than democratizing it
arXiv 2608.24720 (submitted 2026-08-25)
Stack layer / Threat pattern
QWED-MCP, a Verification Gateway, Passed Attacker Math Straight to SymPy parse_expr (CVE-2026-55546, 9.8)
GitHub Security Advisories