|
|
|
|
|
by XiaHua
16 days ago
|
|
That's a great example. It's exactly the kind of behavior we think deserves more attention. It's not a traditional vulnerability but it can significantly influence an agent's decision-making. Today, mcp-xray (https://github.com/traceforce/mcp-xray) can be used to dynamically (not just statically) test against your MCPs. It can detect security vulnerabilities such as code execution, SSRF, path traversal, authorization bypass, input injection, DoS etc. You can find us at demo labs during DEF CON this year. That said, we think behavioral influence is an important problem and it's an area we're interested in exploring next. |
|
I think the point a few people are making is right that its not sufficient to be the best at one layer like the device endpoint. AI governance needs to be coordinated over a number of surfaces. We started with an MCP gateway and drilled down to on-device agents. I imagine you might end up doing the same the other way around.