Vibe CodingMCP Ecosystem Security Audit 118 Findings 194 Packages AgentAuditDEV Community·high signalXBlueskyLinkedInCopy linkAgentAudit scanned 194 MCP packages finding 118 vulnerabilities including 14 critical/high with shell injection and credential leakageSourceSource pageDEV Community↳ Follow the threadPolicy dependency / Stack layerVercel Sandbox can now run Terminal-Bench, SWE-bench and OSWorld with a single --env vercel flagVercel ChangelogStack layer / Threat patternOpenAI ships Astra for Law, scoring 54.0% on Vals Legal Research Bench against 38.7% for base Astra with web searchOpenAI BlogStack layer / Threat patternPattern: identity and account boundaries are now a named class of coding-agent bugGitHubStack layer / Threat patternDeepSeek V4.1 Flash Popped All 11 Vulnerable Targets in Enclave's Offensive Security Benchmark for $5.14Enclave (model release corroborated by DeepSeek) / Hacker News (167pts, 66 comments)Stack layer / Threat patternJan Schauma: Finding Thousands of AI-Discovered Vulnerabilities Has Not Made Anyone Safernetmeister.org / Hacker News (331pts, 282 comments)Policy dependency / Stack layerLangChain ships a first-party integration that deliberately does not wrap the vendor's SDKGitHubStack layer / Threat patternFive new MCP server CVEs, and four of them are the same bug: a network listener with no authenticationNVDStack layer / Threat pattern157 open-source agent projects with 100+ stars audited: safeguards are applied inconsistently across equivalent execution routesarXiv 2609.17698