DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Mapping mcp.json Misconfigurations to the OWASP MCP Top 10

Mapping mcp.json Misconfigurations to the OWASP MCP Top 10

1
Comments
3 min read
sentinel-scan-cli vs Cisco mcp-scanner vs Snyk Agent Scan: comparing open-source MCP security scanners

sentinel-scan-cli vs Cisco mcp-scanner vs Snyk Agent Scan: comparing open-source MCP security scanners

1
Comments
7 min read
AWS Security Events Through the Lens of the Seven MITRE ATT&CK Tactics

AWS Security Events Through the Lens of the Seven MITRE ATT&CK Tactics

1
Comments
12 min read
I Rate-Limited My Own API. Then I Found a Way to Bypass It Myself.

I Rate-Limited My Own API. Then I Found a Way to Bypass It Myself.

Comments
3 min read
Two Strangers Built an Agent Mandate Protocol in My Comments. It Still Needs a Regulator.

Readers designed a payment protocol

Two Strangers Built an Agent Mandate Protocol in My Comments. It Still Needs a Regulator.

23
Comments 72
5 min read
Building a Secure Self-Hosted Observability Pipeline for an AI Evaluation Platform

Building a Secure Self-Hosted Observability Pipeline for an AI Evaluation Platform

2
Comments
8 min read
What a Zero-Network MCP Scanner Can (and Can't) Catch: All 10 Heuristics, Honestly

What a Zero-Network MCP Scanner Can (and Can't) Catch: All 10 Heuristics, Honestly

Comments
4 min read
Your AI Agent Will Follow a Stranger's Instructions. Here's How I Actually Test For It.

Your AI Agent Will Follow a Stranger's Instructions. Here's How I Actually Test For It.

5
Comments 4
5 min read
Attestkeep 1.0 is out, and three readers changed it before it shipped

Attestkeep 1.0 is out, and three readers changed it before it shipped

Comments
8 min read
Catch MCP Tool-Poisoning and Prompt-Injection Regressions on Every PR (GitHub Actions + pre-commit)

Catch MCP Tool-Poisoning and Prompt-Injection Regressions on Every PR (GitHub Actions + pre-commit)

Comments
6 min read
Stop XSS Attacks Cold: An Introduction to Content Security Policy (CSP)

Stop XSS Attacks Cold: An Introduction to Content Security Policy (CSP)

1
Comments
3 min read
What GitHub's pull_request_target changes break in the 1,000 most-starred repositories

What GitHub's pull_request_target changes break in the 1,000 most-starred repositories

Comments 2
4 min read
Confused Deputy: The Old Bug That AI Agents Keep Reintroducing

How AI agents amplify ancient security flaws

Confused Deputy: The Old Bug That AI Agents Keep Reintroducing

7
Comments 8
9 min read
I Added Cryptographic Receipts to MCP Tool Calls in 20 Lines of Code

I Added Cryptographic Receipts to MCP Tool Calls in 20 Lines of Code

1
Comments
8 min read
Static-scanning MCP tool manifests before you install them

Static-scanning MCP tool manifests before you install them

Comments
2 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.