MCP Security: What to Check in Your mcp.json
A design flaw in the Model Context Protocol (MCP) STDIO transport passes configuration values directly into shell execution without sanitization, allowing anyone who can influence the config file to e…
A design flaw in the Model Context Protocol (MCP) STDIO transport passes configuration values directly into shell execution without sanitization, allowing anyone who can influence the config file to e…
Testing MCP servers with real AI models is essential because servers that pass wire-level tests can fail when models attempt to use them. A developer explains that the semantic layer—whether a model c…
A developer and their team built a functional MCP server prototype using FastMCP to let AI assistants interact with an accounting API through natural language queries. The server wrapped API endpoints…
The article details the author's practical response to two recently disclosed MCP security vulnerabilities, including a critical nginx-ui flaw (CVE-2026-33032, CVSS 9.8) and a STDIO transport design f…