MCP Security Research
Independent vulnerability research for the AI agent ecosystem. Discovered by CraftedTrust Touchstone.
Published Advisories
Subscribe via RSSNo advisories published yet. Active research is underway.
Advisories will appear here as vulnerabilities complete the coordinated disclosure process.
The Touchstone 7-Domain Assessment Model
Full Check ReferenceOAuth 2.1 implementation, PKCE enforcement, token storage, HTTPS enforcement, scope analysis, session management, RFC 8707 compliance.
Prompt injection in tool schemas, parameter poisoning, obfuscated payloads, tool shadowing, rug pull detection, dangerous capability combinations.
SSRF via tool parameters, cloud metadata endpoint access, command injection, SQL injection, path traversal, URL scheme validation.
Credential patterns in schemas, PII exposure, secrets in error messages, sensitive data in URL parameters, cross-server data leakage.
npm provenance verification, known CVE matching, typosquat detection, maintainer reputation, source repo verification, abandonment detection.
Network binding audit, TLS enforcement, rate limiting, CORS configuration, error handling, security headers, DNS rebinding protection.
Guardrail bypass patterns, response size limits, timeout enforcement, concurrent request handling, kill switch presence.