NewsMCP Server Security Audit 14 Critical High Findings Across 194 PackagesDEV Community·high signalXBlueskyLinkedInCopy linkAgentAudit audited 194 MCP packages. 14 critical/high findings including command injection and credential leakage.SourceSource pageDEV Community↳ Follow the threadShared entity / Stack layerAgentAudit attaches to a running agent and scores its trace on ten dimensions, exposing 95.1 vs 22.6 trust spreads at similar task completionarXivShared entity / Stack layerClaude Code MCP servers configured as `http` never connected if the server only spoke legacy HTTP+SSEGitHubPolicy dependency / Stack layerCROSS-CATEGORY: Three Independent Agent-Action Gates Shipped in 48 Hours, All Judging the Command Against Stated IntentProduct Hunt, github.com/AGGIB/Stroq and rewarelabs.com (three independent sources; the 72% figure is Reware's own)Policy dependency / Stack layerGitHub Code Quality lets you hand 25 findings to Copilot in one action and get a PR backGitHub ChangelogStack layer / Threat pattern16% of 3,171 public agent-harness setups carry a confirmed security defect, and 3.8% ship a skill that pre-approves your shellarXivPolicy dependency / Stack layerMCP Inspector 2.6.0 raised its declared hono floor rather than trusting its lockfile, and documented whyGitHubStack layer / Threat patternEdge0 runs a 35B MoE on Apple Silicon in 2.9 GB of active memory by streaming experts off SSDGitHubStack layer / Threat patternA weaker agent recovered 80% of a stronger proprietary agent's capability gap from black-box execution differences alonearXiv 2609.07131