ResearchMCPShield Plug-in Security Layer Raises Defense 10 to 95 PercentarXiv·high signalXBlueskyLinkedInCopy linkUndefended MCP agents achieve 10% defense rate. MCPShield adds pre-invocation probing, runtime isolation, post-invocation trace reasoning to reach 95%.SourceSource pagearXiv↳ Follow the threadShared entity / Policy dependencyClaude Agent SDK for Python 0.2.140 adds MCP 2.x in-process servers and a structured ResultError instead of exit code 1GitHub (anthropics/claude-agent-sdk-python)Shared entity / Stack layerMastra 1.60.0 adds opt-in support for the stateless MCP 2026-07-28 revision and multi-round elicitationGitHub (mastra-ai/mastra)Shared entity / Policy dependencyKent C. Dodds ships agent-discovery endpoints in Kody: /.well-known/, markdown homepages, and RFC 8288 Link headers for unconnected agentsGitHub (kentcdodds/kody)Stack layer / Threat patternProof-of-Execution Memory: one LLM rewrite defeats the SENTINEL memory defense entirely, and stronger models are more vulnerablearXivShared entity / Stack layerFuXi Reaches 1,304 Stars as a Single-Binary Terminal Coding Agent, but Ships Under a Proprietary LicenseGitHubStack layer / Threat patternHow you lay out your repo changes prompt-injection success: highly modular workspaces measurably lower attack success ratearXiv 2608.14876Policy dependency / Stack layerCompose agent guardrails as an algebra instead of a rule list: 94.8% of policy-violating events intercepted while keeping 86.9% task completionarXiv 2608.16402Stack layer / Threat patternSemaPLC Puts a Verification Gate on PLC Code Generation and Shows Runtime Execution Separates Models Where Static Scoring Does NotarXiv (via HuggingFace Daily Papers)