// Archive
MCP & supply chain
Vetting MCP servers, agent config and secrets, and the AI supply chain — the dependencies an agent trusts without you ever reviewing them.
// Reference
The attack surface, mapped →
Every technique and tool from this category, organized by layer.
Categories
- NOT-003Your AI Gateway Is on the KEV Catalog NowCISA put LiteLLM, Starlette, and Kestra on the KEV catalog on the same day. The AI plumbing you never inventoried is the part being exploited in the wild.#ai-security#mcp#api-security5 min read
- NOT-002How to Vet an MCP Server Before You Install It97M+ monthly downloads, 8.5% OAuth adoption, 82% path-traversal exposure. A five-step workflow for deciding whether a specific MCP server deserves a place in your config.#agentic-ai#ai-security#mcp12 min read
- NOT-001Your AI Agent Config Is Leaking SecretsThe files that configure your coding agent — .mcp.json, .claude/settings.json, the system prompt — are plaintext on disk and read by code that executes on your behalf. Most of them contain secrets, over-broad permissions, or both. Here's the five-minute audit.#agentic-ai#ai-security#mcp5 min read