I implemented identity, policy, credential injection, audit and isolation for an MCP gateway—then traced the two-call attack those controls could authorize correctly and still lose to.
From red-team engagements to leading security operations. I write about purple teaming, detection, secure architecture, and the open-source tools I build. Evidence over assertions.
I implemented identity, policy, credential injection, audit and isolation for an MCP gateway—then traced the two-call attack those controls could authorize correctly and still lose to.
MCP makes connecting AI agents to tools so easy that the governance question arrives after the connections are live. Part 1 of a series on MCP security — the structural problem: there's no single place to ask whether a tool call should happen.
How a runtime gateway mediates every AI-agent tool call — one port, six checks, per-identity profiles, and credentials the agent never holds. Part 2 of a series on MCP security.