Tool
Free browser-local Model Context Protocol security checker for MCP server configuration risks: shell wrappers, broad filesystem access, hardcoded secrets, unpinned packages, remote URLs, Docker socket exposure, and excessive permissions.
Hub
A practical hub for Model Context Protocol security, token handling, SSRF prevention, and secure AI integrations.
Topic
Model Context Protocol security guidance for tokens, tools, SSRF, local servers, and enterprise integrations.
Blog
Model Context Protocol can make AI tools dramatically more useful, but it also expands trust boundaries. Security teams should treat MCP like a privileged integration layer: sandbox servers, minimize scopes, block token passthrough, defend against SSRF, and review every tool as a potential remote-action surface.
Template
Copy-ready AI acceptable use policy, incident response playbook, MCP review checklist, CISO board memo, coding assistant rollout, and vendor questionnaire.
Hub
Central HackWednesday hub for AI agents, LLM security, model gateways, MCP, coding assistants, SOC, AppSec, CISO controls, and incident response.
FAQ
Curated AI security questions and answers for CISOs, SOC teams, AppSec, cloud security, developers, LLM security, AI agents, model gateways, MCP, and shadow AI.
Brief
A recurring brief for AI security leaders tracking model risk, agent security, MCP, supply chain attacks, and practical controls.
Challenge
A five-minute AI security tabletop challenge for coding-agent token leaks, prompt injection, MCP config risk, runaway retries, and production-change approval.
Page
A practical guide to AI security tools for model gateways, coding agents, MCP security, SOC copilots, CNAPP, SIEM, and vulnerability management.
Checklist
A practical CISO checklist covering approved tools, model gateways, agent identity, MCP risk, coding assistants, logging, and incident response.
Hub
Identity, provenance, runtime controls, model gateways, MCP security, and non-human identity patterns for governing AI agents.
Topic
Controls for AI agents, MCP servers, coding assistants, browser actions, tool use, and autonomous workflows.