AI agent security
5 posts
MCP is an attack surface, not a feature
MCP puts data and control in one channel and runs the model's tool calls with the user's full authority. Why the design fails, from the attacker's view.
A smarter model would have leaked it too.
GitHub's AI agent leaked private repos not from a bug but a design failure. How two-plane architecture, scoped tokens, and deterministic validation stop it.
An open door where the gate should be
GitHub's AI agent returned private repo content when tricked, proving it holds read reach across the private boundary with no enforced refusal.
DayBreak doesn't make your systems vulnerable
A capable security model like DayBreak doesn't add new risk - it exposes that your agent controls were calibrated for a model too weak to exploit them.
One cent compromises a banking AI agent
A one cent transfer claimed to manipulate a banking AI agent proves transaction value does not measure the risk of input to an autonomous system.