cyberivy

Search results for “MCP”

Full-text search across every article: title, summary, plain-language explanation, and the complete text — archived stories included. Typos are fine.

90 results for “MCP”

  1. gemini-bridge flaw exposes the file risk in local agents

    #AI Security#MCP#gemini-bridge

    on July 31, 2026. The Python package connects MCP-based agents with Google’s Gemini CLI. That bridge could read local files in certain versions when a caller supplied paths through the files parameter. This is not a

  2. BadHost shows how fragile many AI agent servers are

    #AI Security#BadHost#Starlette

    used for LLM gateways, vLLM servers, LiteLLM proxies, MCP servers, evaluation dashboards and internal agent UIs. Those systems often hold API keys, mailbox access, model-management rights or tool-execution capabilities.

  3. Arcade gives AI agents controlled rights to real tools

    #Arcade.dev#AI Agents#MCP

    What Arcade actually does Arcade describes itself as an MCP runtime for production agents. Developers can expose tools and integrations without giving every agent raw API keys, service accounts, or broad superuser

  4. AURI Brings AppSec Into AI Coding Workflows

    #AURI#Endor Labs#AI Security

    with a product page, developer page, documentation, MCP integration, CLI, GitHub Action and GitHub app. What AURI actually does AURI brings security knowledge into the tools where developers already work. Endor Labs says

  5. Amazon Q flaw shows the repo risk in coding agents

    #Amazon Q#AI Security#MCP

    read project configuration, and use protocols such as MCP to reach tools. That is where convenience turned into a trust boundary. What the Amazon Q flaw actually does According to Wiz, Amazon Q loaded a .amazonq/mcp.json

  6. Pipelock puts a firewall between agents and the internet

    #Pipelock#AI Security#MCP Security

    not just write text, but triggers real network requests, MCP tool calls, or WebSocket communication? The project positions itself as an agent firewall and egress-control layer between an agent and the internet. The

  7. AIMap finds exposed AI endpoints before attackers do

    #AIMap#AI Security#MCP Security

    it. This is not only about classic APIs. It also includes MCP servers, Ollama instances, vLLM or LiteLLM proxies, LangServe apps, Gradio demos, and ComfyUI nodes. The value is concrete: security teams can use AIMap to

  8. DBX connects database work to AI agents with clear permissions

    #DBX#Database Tools#MCP

    a command line, a built-in SQL assistant, and a separate MCP server. The project claims support for more than 90 database systems and an application size of roughly 20 MB. It is developed under Apache 2.0 and was

  9. Databox Skills Marketplace turns analytics into usable skills

    #Databox#Analytics#MCP

    matter. They can run a prepared skill that uses Databox MCP to access defined live data. This is a concrete AI tool, not a general analytics trend. Users receive skill files, setup guides, metric maps, and

Browse all AI news in the archive