We scanned a single machine. 1.8 seconds.
Found:
├─ 9 AI agents
├─ 6 MCP servers with findings
├─ SSH private key exposure
├─ Hardcoded Slack token
├─ 2 toxic attack chains
└─ A .cursorrules file stealing credentials
Your machine probably has the same.
Free. Open source. No API key.
Your AI agent is only as secure as the prompts behind it.
We built AgentSeal to find out exactly how secure that is.
What it does:
✓・ Runs 150+ attack probes (prompt injection, extraction, encoding tricks, social engineering)
✓・ Tests MCP tool poisoning, RAG pipeline attacks, and maps your agent's behavioral genome
✓・Tells you exactly what broke, why it broke, and how to fix it. Full remediation guidance, not just a score.
✓・Works with local models (Ollama, vLLM, LM Studio) and cloud (OpenAI, Anthropic)
✓・ Available as npm and pip package. Open source.
We're actively looking for contributors・↓
https://t.co/bQjxHf1KNn
Completely agree with you on this. The real problem is bigger, though. There are full platforms openly building professional engagement farming systems where projects pay creators in crypto to follow, like, RT, and comment at scale. Small Telegram sellers get banned, but these public platforms, doing the same thing at an industrial level, seem to operate freely. This is exactly why real content struggles to reach the right people. X needs to address this, too.
@DarioAmodei we have been building open-source AI agent security, red-teaming, MCP scanning, runtime guard, compliance - all powered by Claude.
Hope AgentSeal grows large enough to join you soon.
@birdabo mythos escaped a locked sandbox. meanwhile we have scanned thousands of MCP servers and most of them hand the AI unrestricted shell access by default. The call is coming from inside the house. 😄
@logangraham We have been scanning MCP servers for exactly this class of risk. Found confirmed exploits in repos with 70K+ stars. AI finding bugs in AI infrastructure is the next frontier. Glad to see Anthropic leading it.
https://t.co/nD7OAbse5X
Introducing Project Glasswing: an urgent initiative to help secure the world’s most critical software.
It’s powered by our newest frontier model, Claude Mythos Preview, which can find software vulnerabilities better than all but the most skilled humans.
https://t.co/NQ7IfEtYk7
⚠️ Supply chain attack in progress: someone is squatting Anthropic-internal npm package names targeting people trying to compile the leaked Claude Code source.
`color-diff-napi` and `modifiers-napi` — both registered today, same person, disposable email. Do NOT install them. 🧵
Static analysis says "this MCP server is dangerous," but is it actually exploitable?
we tested 6 high-star servers in a controlled lab. planted fake credentials. connected the way a real client would.
28/28 findings confirmed. 17 secrets extracted.
https://t.co/2Xe4O5Nsfc
@snyksec@owasp@simonw
@chiefofautism Funny timing - we've been scanning MCP servers for exactly this. 7,500+ analyzed so far, 40%+ have real vulnerabilities. Some with 10k+ GitHub stars.
You can look up any server on our public registry: https://t.co/nD7OAbse5X
We scanned a single machine. 1.8 seconds.
Found:
├─ 9 AI agents
├─ 6 MCP servers with findings
├─ SSH private key exposure
├─ Hardcoded Slack token
├─ 2 toxic attack chains
└─ A .cursorrules file stealing credentials
Your machine probably has the same.
Free. Open source. No API key.
@TukiFromKL thats why we came up with this MCP registry which can help users to give depth analysis before they download anything https://t.co/nD7OAbse5X