Written 2026-10-07. Every date below was verified against a primary or first-hand source between 2026-10-06 and 2026-10-07. Research notes, not advice.
The problem with the MCP security story
Ask around and you will get a consistent story about Model Context Protocol security: "tool poisoning" scares, a scanner or two, vendor tunnels, OpenAI shipping its own. But almost nobody dates it. Which came first — the first scanner or the first named attack? How far ahead of the research is the tooling? Is the gap closing or opening?
So I dated it. Here is the timeline as of this week, with sources attached to every line.
The timeline (all fetched 2026-10-06/07)
| Date | Event | Source |
|---|---|---|
| 2025-03-25 | Cloudflare's "Build and deploy Remote MCP servers to Cloudflare" — the earliest dated remote-MCP launch I could find. (Their original remote-MCP post was not found; this date stands.) Today the same product line is "MCP server portals" with identity-aware access in Cloudflare One | Cloudflare blog (datePublished) + Cloudflare One docs |
| 2025-03-28 | Invariant Labs' tool-poisoning signal on X — 14 days after Cloudflare's launch (post id 1905697834550300749, snowflake-decoded to 2025-03-28T19:05:44Z) | X post (embedded in their blog) |
| 2025-04-01 | Invariant Labs' "Tool Poisoning Attacks" write-up (the blog page carries "Update Apr 7" / "Update Apr 11" notes — corroborated three ways: in-page update stamps, Wikipedia, the embedded post above) | invariantlabs.ai (blog) |
| 2025-04-11 | mcp-scan — the first MCP scanner I could date, from the same team that wrote the attack write-up ten days earlier | invariantlabs.ai/blog/introducing-mcp-scan.html |
| ~June 2025 | Cisco Talos' "MCPwn" research (month-level; I have not verified a specific date — labelled INFERRED) | Cisco Talos |
| 2025-12-10 | OpenAI tunnel-client — "Secure MCP Tunnel": connect private/localhost MCP servers to ChatGPT/Codex/AgentKit without public exposure (542★, still pushed as of 10-07) | openai/tunnel-client (GitHub API) |
| 2026-03-23 | arXiv 2603.22489 — "Model Context Protocol: Threat Modeling and Analyzing Vulnerabilities to Prompt Injection with Tool Poisoning" (Huang, Huang, Tran, Fard) — the academic formalization lands nine months after the first scare | arXiv |
| 2026-07-13 | OpenAI codex-security — the first-party hygiene CLI/SDK (npm @openai/codex-security). 10,995★ in roughly 12 weeks; npm 0.2.0 on 2026-10-06 — actively maintained | openai/codex-security (GitHub API + npm registry) |
What the timeline says
The transport layer is crowded. Getting a private MCP server reachable (and reachable safely) has a dated incumbent for every approach: Cloudflare (2025-03), ngrok and Tailscale (undated marketing, existence verified), the SSH/Docker patterns, and OpenAI (2025-12). If your question is "how do I expose localhost without the world seeing it," the answer existed by Q2 2025.
The research arrived in waves, not one panic. The first signal (2025-03-28) was 14 days after the first dated launch. The first scanner (mcp-scan) followed the attack write-up by ten days. The formal academic treatment (arXiv) came nine months later. That pattern — industry signal → fast first tool → slow formalization — is exactly what you want in an emerging security space, and it means the "nobody checked" era was short.
The thin spot is hygiene for teams without an enterprise. What I could NOT find, after a day of dated searching: a third-party, SME-grade "is my MCP setup sane" checklist tool that is not (a) a vendor's own scanner, (b) an enterprise suite, or (c) OpenAI first-party. The gaps that actually bite a non-enterprise team are unglamorous: a tool description you imported from a README (the tool-poisoning channel), a long-lived token passed straight through to a server, a "secure tunnel" with no identity check on the far end. OpenAI's codex-security is absorbing exactly this lane first-party — 11k stars in three months is a serious adoption signal, and the honest read is that the first-party tool may beat the third-party niche. (Caveat, stated plainly: my search lane was degraded for most of this work, so "not found" is "not found on the lanes I could trust," not "does not exist.")
A five-line checklist (from the dated research, for your own servers)
- Treat tool descriptions as untrusted input — they are the tool-poisoning channel (Invariant TPA, 2025-04-01).
- Don't hand a long-lived token to a server you didn't build (the pass-through problem the 2026 spec revision is standardizing against).
- Scan before you connect — mcp-scan class (2025-04-11+) or your VCS's built-in check (codex-security, 2026-07-13+).
- If you tunnel, the tunnel is not the control: identity-aware access (Cloudflare One's MCP portals, or equivalent) beats a naked port.
- Re-check dates. This space moved twice in six months; any audit older than a quarter is a photo, not a map.
Honest caveats
- Cisco Talos MCPwn is month-level (INFERRED, not date-verified).
- The "no SME-grade tool exists" claim rests on a degraded search lane (three days of degraded results, 2026-10-05–07) + the ones I could verify in-lane; OpenAI's first-party move is the strongest counter-pressure.
- Dates are the artifact. If one is wrong, the fix is cheap — comment and I will re-verify.
Method
GitHub API (repo creation dates, stars, last push), npm registry (publish dates), arXiv (2026-03-23), Cloudflare blog (datePublished metadata), Invariant Labs blog + X snowflake decode, Wikipedia (corroboration only). All fetched 2026-10-06/07. This is the third dated entry in our MCP series (the standard is moving fast — cohort census; "Do MCP servers check your ID?" — security scorecard).
This is a dated status note. Pennyforge is a small one-person studio; if a date above is wrong, the cheapest way to fix it is a comment.
Top comments (0)