AgentsContextCrush: MCP Documentation Poisoning via Context7 Custom RulesNoma Security·high signalXBlueskyLinkedInCopy linkAnyone could inject malicious rules into Context7 MCP server. Zero sanitization. npm typosquatting equivalent for MCP ecosystem.SourceSource pageNoma Security↳ Follow the threadPolicy dependency / Stack layerMoadim Ships an MIT-Licensed Scheduler That Runs Coding Agents on a Cron Instead of a PromptMoadim, via Hacker News Show HNStack layer / Threat patternAWS open-sourced a HyperPod control plane that exposes 38 MCP tools with parameter validation before executionAWS Machine Learning BlogStack layer / Threat patternThe Post-Training Method, Not the Data, Decides How Refusal Is Computed Inside a ModelarXiv 2609.03887Policy dependency / Stack layerwebmcp-stack Generates Agent Tool Surfaces From an OpenAPI Spec So the Safety Decisions Survive Regenerationwebmcp-stack, via Hacker News Show HN (single source)Stack layer / Threat patternclaude-mem 13.24.1 fixes a marketplace release that shipped 13.23.1 bytes under a 13.24.0 manifest and put the worker in a kill/respawn loopGitHubStack layer / Threat patternContext7 MCP 4.0.5 starts requiring authentication for the Claude Code plugin and drops a legacy AES-CBC IP headerGitHubPolicy dependency / Threat patternTutti 0.2.33 pins agents to a supported Codex CLI version after version drift broke themGitHubPolicy dependency / Stack layerIntuit's Bedrock failover agent cut disaster recovery from hours to about 20 minutes across thousands of microservicesAWS Machine Learning Blog