AAffixIOinaffixio.hashnode.dev·2d ago · 5 min readAn approved MCP tool definition is not a forever allowPillar Security's Deadbugz write-up is a useful reminder for anyone wiring agents to Model Context Protocol servers. A malicious MCP server shipped under a harmless name, behaved like a text formatter00
AAffixIOinaffixio.hashnode.dev·2d ago · 5 min readMCP OAuth metadata is not a tool-call permissionOn 29 September 2026, The Hacker News covered a high-severity issue in the official Model Context Protocol Python SDK: a malicious MCP server could trick an affected client into handing over OAuth cre00
AAffixIOinaffixio.hashnode.dev·3d ago · 5 min readIndividually correct agent controls can still fail at the boundaryA stack of sound security pieces does not automatically make a sound agent. That is the uncomfortable claim in CONTINUITY, a September 2026 paper on composable LLM agent controls (arXiv:2609.05269). T00
AAffixIOinaffixio.hashnode.dev·3d ago · 6 min readAn agent kill switch without a signed spend receipt is incompleteDigiCert's AI Trust Manager, generally available in mid-September 2026, put a clean phrase into the industry conversation: every AI agent needs a kill switch. The product centres on AI Passports, poli00
AAffixIOinaffixio.hashnode.dev·4d ago · 5 min readMCP server admission is not the same as tool-call permissionThe Model Context Protocol made it ordinary for an agent host to discover tools and dispatch calls. What it did not standardise is trust. A host still tends to take a server identity and a self-declar02CG