DEV Community

MCP Security Deep Dives Series' Articles

Back to Kiell Tampubolon's Series
I Connected 11 MCP Servers. 3 of Them Actually Did Anything.

I Connected 11 MCP Servers. 3 of Them Actually Did Anything.

Comments 2
4 min read
Finishing a Read-Only MCP Server: From 6 Tools to 9

Finishing a Read-Only MCP Server: From 6 Tools to 9

5
Comments 2
3 min read
The MCP attack your code review cannot see
Cover image for The MCP attack your code review cannot see

The MCP attack your code review cannot see

Comments 6
4 min read
My MCP Security Scanner Missed 2026's Worst MCP RCE: Here Is the One-Rule Fix
Cover image for My MCP Security Scanner Missed 2026's Worst MCP RCE: Here Is the One-Rule Fix

My MCP Security Scanner Missed 2026's Worst MCP RCE: Here Is the One-Rule Fix

1
Comments 4
5 min read
MCP 2026-07-28 Went Stateless: A Planted Prompt Is a Credential
Cover image for MCP 2026-07-28 Went Stateless: A Planted Prompt Is a Credential

MCP 2026-07-28 Went Stateless: A Planted Prompt Is a Credential

Comments 2
8 min read
What actually changes when an MCP server leaves your laptop

What actually changes when an MCP server leaves your laptop

Comments 1
3 min read
A happy-path MCP demo proves almost nothing about tenant isolation

A happy-path MCP demo proves almost nothing about tenant isolation

Comments 9
3 min read
Benchmarking My MCP Security Scanner: 14 of 14 Findings, Zero False Positives

Benchmarking My MCP Security Scanner: 14 of 14 Findings, Zero False Positives

Comments 1
2 min read
My Scanner Passed Until I Built a Harness That Lied to It on Purpose

My Scanner Passed Until I Built a Harness That Lied to It on Purpose

3
Comments 10
3 min read
The NSA published 17 pages on MCP security. Here it is as a checklist you can run today

The NSA published 17 pages on MCP security. Here it is as a checklist you can run today

Comments
3 min read
200,000 exposed MCP servers later, the boring checks still win

200,000 exposed MCP servers later, the boring checks still win

Comments
2 min read
5 Kesalahan Keamanan MCP yang Jamak Dilakukan Bisnis Kecil (dan Cara Memperbaikinya Hari Ini)
Cover image for 5 Kesalahan Keamanan MCP yang Jamak Dilakukan Bisnis Kecil (dan Cara Memperbaikinya Hari Ini)

5 Kesalahan Keamanan MCP yang Jamak Dilakukan Bisnis Kecil (dan Cara Memperbaikinya Hari Ini)

Comments
3 min read
What Is MCP Security? Common Attacks and How to Scan Your MCP Servers

What Is MCP Security? Common Attacks and How to Scan Your MCP Servers

Comments 7
5 min read
How to Audit an MCP Server Manifest for Prompt Injection in Tool Descriptions

How to Audit an MCP Server Manifest for Prompt Injection in Tool Descriptions

Comments
5 min read
A fake MCP server spent three months earning trust. The tells were there

A fake MCP server spent three months earning trust. The tells were there

1
Comments 14
3 min read
MCP Costs 72% of Your Context: The Fix Pi Shipped
Cover image for MCP Costs 72% of Your Context: The Fix Pi Shipped

MCP Costs 72% of Your Context: The Fix Pi Shipped

Comments
6 min read
I Audited the MCP SDK OAuth Fix: 3 Checks Upgrading Misses
Cover image for I Audited the MCP SDK OAuth Fix: 3 Checks Upgrading Misses

I Audited the MCP SDK OAuth Fix: 3 Checks Upgrading Misses

Comments
6 min read
Read-Only Postgres MCP Servers Fail With 1 SQL Keyword
Cover image for Read-Only Postgres MCP Servers Fail With 1 SQL Keyword

Read-Only Postgres MCP Servers Fail With 1 SQL Keyword

Comments
6 min read
I Traced 29 CVEs in One MCP Server to 4 Root Causes
Cover image for I Traced 29 CVEs in One MCP Server to 4 Root Causes

I Traced 29 CVEs in One MCP Server to 4 Root Causes

Comments
10 min read
MCP Servers Had a Rough 48 Hours: 4 Unauthenticated CVEs
Cover image for MCP Servers Had a Rough 48 Hours: 4 Unauthenticated CVEs

MCP Servers Had a Rough 48 Hours: 4 Unauthenticated CVEs

Comments
9 min read
Threat Modeling the Model Context Protocol: Securing Agentic Tools with mcpscan
Cover image for Threat Modeling the Model Context Protocol: Securing Agentic Tools with mcpscan

Threat Modeling the Model Context Protocol: Securing Agentic Tools with mcpscan

Comments
5 min read