Protocol Intelligence

The MCP
Ecosystem Blog

Security research, tool discovery patterns, and infrastructure insights for developers building with the Model Context Protocol.

Security
Tool poisoning, supply chain, schema drift
Discovery
BM25, semantic routing, context management
Infrastructure
Proxies, gateways, sandboxing, OAuth
Ecosystem
Standards, conferences, community trends
$

Latest Transmissions

Nobody Is Checking: What Three Independent Scans of 14,000+ MCP Servers Reveal

Three independent teams scanned 14,000+ MCP servers in 30 days. All found the same vulnerabilities. All ended with the same recommendation. None of them could enforce it.

mcpsecurityscanningecosystemadmission-control

MCP Is Deprecating Sampling, Roots, and Logging: What It Means for the Ecosystem

SEP-2577 proposes removing three core MCP features simultaneously. The protocol is scope-reducing to become a lean stateless tool-calling layer. Here is what builders need to know.

mcpprotocolsamplingdeprecationecosystem

A Malicious MCP Server Can Inflate Your API Bill 658x — And Standard Defenses Miss It 97% of the Time

A new class of MCP attack turns tool responses into a billing amplifier. A session that should cost $0.10 costs $65.80. The schema is clean, the task completes, and 97% of standard defenses never notice.

mcpsecurityattackeconomicsresearch

Three Governance Gaps Nobody Instruments in Multi-Agent Systems

Three independent teams arrived at the same conclusion this week: multi-agent systems fail silently because nobody instruments delegation, escalation, or reputation. Here are the practical instrumentation points.

multi-agentgovernancedelegationobservabilitymcpa2aagent-coordination

MCP Server-Initiated Sampling: The Spec Feature That Becomes an Attack Vector

MCP sampling lets servers request LLM completions through the client. Unit42 research shows how this legitimate spec feature enables prompt injection, cross-server poisoning, privilege escalation, and data exfiltration.

mcpsecuritysamplingprompt-injectionunit42spec