The whole MCP security platform in one schema, then each block reduced to the fields and checks you cannot skip - each traced to an RFC or a tested invariant, with the reference implementation's real status next to the contract it does not yet meet.
From red-team engagements to leading security operations. I write about purple teaming, detection, secure architecture, and the open-source tools I build. Evidence over assertions.
The whole MCP security platform in one schema, then each block reduced to the fields and checks you cannot skip - each traced to an RFC or a tested invariant, with the reference implementation's real status next to the contract it does not yet meet.
A signed trust envelope for MCP tool results, and the independent consumer that verifies it and refuses - across eight attacks including a live man-in-the-middle. What the signature proves, what it doesn't, and where I had to find another way.
I implemented identity, policy, credential injection, audit and isolation for an MCP gateway—then traced the two-call attack those controls could authorize correctly and still lose to.
MCP makes connecting AI agents to tools so easy that the governance question arrives after the connections are live. Part 1 of a series on MCP security — the structural problem: there's no single place to ask whether a tool call should happen.
How a runtime gateway mediates every AI-agent tool call — one port, six checks, per-identity profiles, and credentials the agent never holds. Part 2 of a series on MCP security.