DEV Community

Kiell Tampubolon profile picture

Kiell Tampubolon

Security Engineer & Technical Writer | AI Security, MCP, Developer Security & Automation

Location Singapore Joined Joined on  Personal website https://www.kielltampubolon.id/ github website
June Solstice Game Jam Completion
GitHub Copilot "Finish-Up-A-Thon" Challenge Completion
Gemma 4 Challenge Completion
2 Week Community Wellness Streak
Google Cloud NEXT Writing Challenge Completion Badge
OpenClaw Challenge Completion Badge
1 Week Community Wellness Streak
Writing Debut
My agents kept forgetting each other, so I wrote a protocol about it

My agents kept forgetting each other, so I wrote a protocol about it

1
Comments
7 min read

Want to connect with Kiell Tampubolon?

Create an account to connect with Kiell Tampubolon. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
FortiMail Zero-Day: 3 Checks Before You Trust the Patch

FortiMail Zero-Day: 3 Checks Before You Trust the Patch

Comments
7 min read
Math.random Signed the Cookies: 12 Requests to HFS Admin

Math.random Signed the Cookies: 12 Requests to HFS Admin

Comments
8 min read
AI Agent Chained 2 Zero-Days to Root in Seconds: 4 Checks

AI Agent Chained 2 Zero-Days to Root in Seconds: 4 Checks

Comments
6 min read
Threat Modeling the Model Context Protocol: Securing Agentic Tools with mcpscan

Threat Modeling the Model Context Protocol: Securing Agentic Tools with mcpscan

Comments
5 min read
9.8 Windows DNS RCE: 3 Triage Checks Before It Repeats SigRed

9.8 Windows DNS RCE: 3 Triage Checks Before It Repeats SigRed

Comments
6 min read
Mullvad Public DNS Shuts Down Nov 2: 5 Checks I Ran First

Mullvad Public DNS Shuts Down Nov 2: 5 Checks I Ran First

Comments
8 min read
Shopify Left React Native: 4 Questions Before You Follow

Shopify Left React Native: 4 Questions Before You Follow

Comments
6 min read
I Traced CrewAI's Sandbox CVE: 9 Names Missed the Runtime

I Traced CrewAI's Sandbox CVE: 9 Names Missed the Runtime

Comments
8 min read
Artifactory Is Under Active Attack: 3 Checks in 30 Minutes

Artifactory Is Under Active Attack: 3 Checks in 30 Minutes

Comments
8 min read
MCP Servers Had a Rough 48 Hours: 4 Unauthenticated CVEs

MCP Servers Had a Rough 48 Hours: 4 Unauthenticated CVEs

Comments
9 min read
I Traced the Jev Repo Wave: 5 Checks Before You Star It

I Traced the Jev Repo Wave: 5 Checks Before You Star It

Comments
8 min read
Codex Sandbox Escape: 3 Checks Before You Open Another Repo

Codex Sandbox Escape: 3 Checks Before You Open Another Repo

Comments
8 min read
I Traced 29 CVEs in One MCP Server to 4 Root Causes

I Traced 29 CVEs in One MCP Server to 4 Root Causes

Comments
10 min read
NetScaler RCE: 3 Checks Before Your Next Patch Window

NetScaler RCE: 3 Checks Before Your Next Patch Window

Comments 1
5 min read
I Traced Unbound's DNSSEC Heap Overflow: 4 Checks to Run

I Traced Unbound's DNSSEC Heap Overflow: 4 Checks to Run

Comments
7 min read
I Traced AgentCore's Package Injection Bug Through 2 Fixes

I Traced AgentCore's Package Injection Bug Through 2 Fixes

Comments
6 min read
I Traced vm2's 9.5 Sandbox Escape to a Missing Regex Boundary

I Traced vm2's 9.5 Sandbox Escape to a Missing Regex Boundary

Comments
6 min read
I spent 4 hours getting a Copilot Studio agent to read Entra audit logs. Here is what actually broke.

I spent 4 hours getting a Copilot Studio agent to read Entra audit logs. Here is what actually broke.

Comments
8 min read
Read-Only Postgres MCP Servers Fail With 1 SQL Keyword

Read-Only Postgres MCP Servers Fail With 1 SQL Keyword

Comments
6 min read
I Traced MaxKB's 10.0 CVE Through the Advisory and the Code

I Traced MaxKB's 10.0 CVE Through the Advisory and the Code

1
Comments
8 min read
I Read Claude's Biology Discovery as a Pipeline: 5 Lessons

I Read Claude's Biology Discovery as a Pipeline: 5 Lessons

Comments
6 min read
I Audited the MCP SDK OAuth Fix: 3 Checks Upgrading Misses

I Audited the MCP SDK OAuth Fix: 3 Checks Upgrading Misses

Comments
6 min read
MCP Costs 72% of Your Context: The Fix Pi Shipped

MCP Costs 72% of Your Context: The Fix Pi Shipped

Comments
6 min read
5 Skills I Still Learn by Hand While Agents Write Code

5 Skills I Still Learn by Hand While Agents Write Code

1
Comments
6 min read
1,5 Juta Token API Bocor di Moltbook. Token Hygiene Bukan Fitur, Itu Standar Minimal

1,5 Juta Token API Bocor di Moltbook. Token Hygiene Bukan Fitur, Itu Standar Minimal

1
Comments
5 min read
The fake browser extension playbook is back. This time it ships as agent skills

The fake browser extension playbook is back. This time it ships as agent skills

1
Comments 2
5 min read
No CVE needed: how a GitHub issue hijacked an AI agent

No CVE needed: how a GitHub issue hijacked an AI agent

2
Comments 3
5 min read
The payment webhook failure I had to inject on purpose

The payment webhook failure I had to inject on purpose

2
Comments 6
4 min read
How to Audit an MCP Server Manifest for Prompt Injection in Tool Descriptions

How to Audit an MCP Server Manifest for Prompt Injection in Tool Descriptions

Comments
5 min read
How to Build an AI SOC With Tools You Already Own (Copilot Studio, Power Automate, Graph API)

How to Build an AI SOC With Tools You Already Own (Copilot Studio, Power Automate, Graph API)

3
Comments 1
5 min read
What Is MCP Security? Common Attacks and How to Scan Your MCP Servers

What Is MCP Security? Common Attacks and How to Scan Your MCP Servers

Comments 7
5 min read
5 Kesalahan Keamanan MCP yang Jamak Dilakukan Bisnis Kecil (dan Cara Memperbaikinya Hari Ini)

5 Kesalahan Keamanan MCP yang Jamak Dilakukan Bisnis Kecil (dan Cara Memperbaikinya Hari Ini)

Comments
3 min read
200,000 exposed MCP servers later, the boring checks still win

200,000 exposed MCP servers later, the boring checks still win

Comments
2 min read
Your error tracker is an input channel now

Your error tracker is an input channel now

Comments
2 min read
The NSA published 17 pages on MCP security. Here it is as a checklist you can run today

The NSA published 17 pages on MCP security. Here it is as a checklist you can run today

Comments
3 min read
Bayaran Sudah Masuk tapi Status Masih Belum Dibayar: Kenapa Webhook Pembayaran Gagal Diam-diam

Bayaran Sudah Masuk tapi Status Masih Belum Dibayar: Kenapa Webhook Pembayaran Gagal Diam-diam

Comments 1
4 min read
Benchmarking My MCP Security Scanner: 14 of 14 Findings, Zero False Positives

Benchmarking My MCP Security Scanner: 14 of 14 Findings, Zero False Positives

Comments 1
2 min read
Two Agents, One Protocol: My First A2A Test, Including Every Bug on the Way

Two Agents, One Protocol: My First A2A Test, Including Every Bug on the Way

Comments 6
3 min read
Three PRs to Rowboat in 24 Hours, One of Them Taught Me More Than the Others

Highlights the orientation cost of agentic coding

Three PRs to Rowboat in 24 Hours, One of Them Taught Me More Than the Others

3
Comments 9
3 min read
What actually changes when an MCP server leaves your laptop

What actually changes when an MCP server leaves your laptop

Comments 1
3 min read
A valid payment webhook can still be dangerous to process twice

A valid payment webhook can still be dangerous to process twice

Comments 1
4 min read
MCP 2026-07-28 Went Stateless: A Planted Prompt Is a Credential

MCP 2026-07-28 Went Stateless: A Planted Prompt Is a Credential

Comments 2
8 min read
2 CVSS 9.8 Agent Sandbox CVEs Landed the Same Day

2 CVSS 9.8 Agent Sandbox CVEs Landed the Same Day

Comments
6 min read
The Cursor Allowlist Bypass That Starts With a File Named curl

The Cursor Allowlist Bypass That Starts With a File Named curl

Comments 4
4 min read
My MCP Security Scanner Missed 2026's Worst MCP RCE: Here Is the One-Rule Fix

My MCP Security Scanner Missed 2026's Worst MCP RCE: Here Is the One-Rule Fix

1
Comments 4
5 min read
Two ways to reuse a privileged CI token (and my rule only caught one)

Two ways to reuse a privileged CI token (and my rule only caught one)

1
Comments 2
5 min read
We Planted 10 Vulnerabilities to Test Free Semgrep. It Reported 3.

Understanding where free security tools stop

We Planted 10 Vulnerabilities to Test Free Semgrep. It Reported 3.

6
Comments 7
6 min read
Asynchronous Telemetry Blindness in AI Streaming Clients: A PoC Where Text Renders, Billing Stays at Zero

Asynchronous Telemetry Blindness in AI Streaming Clients: A PoC Where Text Renders, Billing Stays at Zero

1
Comments 2
7 min read
Your AI agent is the most over-privileged account you own

Your AI agent is the most over-privileged account you own

1
Comments
4 min read
The MCP attack your code review cannot see

The MCP attack your code review cannot see

Comments 6
4 min read
No human reviewed this article before it went live

No human reviewed this article before it went live

Comments
3 min read
Di era AI, yang menang bukan yang kerja paling banyak

Di era AI, yang menang bukan yang kerja paling banyak

Comments
3 min read
Connecting Sophos Central to a Copilot Studio Agent with Power Automate

Connecting Sophos Central to a Copilot Studio Agent with Power Automate

Comments
4 min read
I gave Claude a memory of everything I browse — here's the architecture

I gave Claude a memory of everything I browse — here's the architecture

3
Comments 10
3 min read
We thought we had location-based MFA. We had something else entirely

We thought we had location-based MFA. We had something else entirely

1
Comments 4
5 min read
Solstice — A Game About Holding the Light

June Solstice Game Jam Submission

Solstice — A Game About Holding the Light

2
Comments
3 min read
Finishing a Read-Only MCP Server: From 6 Tools to 9

Finishing a Read-Only MCP Server: From 6 Tools to 9

5
Comments 2
3 min read
Claude Token Monitor 🚀 — Real-Time Claude Usage HUD for Your Windows Desktop

Claude Token Monitor 🚀 — Real-Time Claude Usage HUD for Your Windows Desktop

Comments
3 min read
AI Agents: The Future of Autonomous Intelligence

AI Agents: The Future of Autonomous Intelligence

1
Comments 2
3 min read
loading...