You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We are researching a specific supply-chain risk in agent stacks and collecting practices from real teams. Not a product pitch — findings will be summarized publicly in this thread.
The risk: tool descriptions your agent obeys can silently change after you approve them — maintainer update, compromised registry, typosquatted package. OWASP codified the class as tool poisoning (MCP03:2025). Install-time scanners check before you connect. Nobody watches after.
7 short questions — answer inline, in writing:
How many third-party MCP servers does your team run, roughly?
Have you ever read the text of a tool description after installing? (yes / no / what is that)
Did an agent ever do something unexpected after a server update? What happened?
Who on your team is responsible for the security of what agents connect to? (name / role / nobody)
How do you decide a server is safe to connect? (gut / checklist / scanner / other)
If a free OSS tool pinned tool descriptions at approval and alerted on any change — would you run it this week? What would stop you?
Gut check: independent maintainer, crypto-only payments, fully open code with on-chain verifiable releases — problem / meh / fine?
Answers from DMs and other channels count too — we will aggregate everything here.
Context: we built a working CI-gate prototype (hash-pinning of tool descriptions, zero-dep) and a public attack corpus with two rug-pull demos — see the repo. The research decides what we build next.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
We are researching a specific supply-chain risk in agent stacks and collecting practices from real teams. Not a product pitch — findings will be summarized publicly in this thread.
The risk: tool descriptions your agent obeys can silently change after you approve them — maintainer update, compromised registry, typosquatted package. OWASP codified the class as tool poisoning (MCP03:2025). Install-time scanners check before you connect. Nobody watches after.
7 short questions — answer inline, in writing:
Answers from DMs and other channels count too — we will aggregate everything here.
Context: we built a working CI-gate prototype (hash-pinning of tool descriptions, zero-dep) and a public attack corpus with two rug-pull demos — see the repo. The research decides what we build next.
All reactions