Policy dependency / Threat pattern
mcp-shell Ships Security Off in One Deploy Path and Bypassable in the Other (CVE-2026-55580/55581/55582)
GitHub Security Advisories
Policy dependency / Stack layer
MCP-Universe RL trains tool-use agents by using MCP servers as the RL environment interface
arXiv
Policy dependency / Stack layer
WebMCP-Phalanx blocks all 80 tool-description injections in a browser agent, then gets bypassed by a malicious tool name called before inspection
arXiv
Stack layer / Threat pattern
Anthropic's own weekly sales digest runs on Claude Code plus a BigQuery MCP connector and nine hand-written content rules
Claude by Anthropic
Policy dependency / Stack layer
Halofy ships an open governance layer for agents with identity, policy, provenance, audit and signed erasure
GitHub
Stack layer / Threat pattern
Cline v4.1.16 fixes hooks resolving from global state, and starts redacting credentials embedded in git remote URLs before they reach the model
GitHub (cline/cline)
Stack layer / Threat pattern
Ornith-1.5 Ships 9B Dense, 35B MoE and 397B MoE Under MIT, With the 397B Claiming 86.0 SWE-bench Verified Against Claude Opus 4.8's 85.8
Hugging Face
Policy dependency / Stack layer
SMITH Trains Tool Creation and Tool Use in One Policy; a 4B Qwen3 Beats an Untrained 30B Tool-Writer at 79.8 Macro Accuracy
arXiv 2608.24571