Vibe CodingMCP Ecosystem Security Audit 118 Findings 194 Packages AgentAuditDEV Community·high signalXBlueskyLinkedInCopy linkAgentAudit scanned 194 MCP packages finding 118 vulnerabilities including 14 critical/high with shell injection and credential leakageSourceSource pageDEV Community↳ Follow the threadPolicy dependency / Stack layerGitHub Code Quality lets you hand 25 findings to Copilot in one action and get a PR backGitHub ChangelogStack layer / Threat pattern16% of 3,171 public agent-harness setups carry a confirmed security defect, and 3.8% ship a skill that pre-approves your shellarXivPolicy dependency / Stack layerMCP Inspector 2.6.0 raised its declared hono floor rather than trusting its lockfile, and documented whyGitHubStack layer / Threat patternMicrosoft's September patch is the largest on record at roughly 972 CVEs, with two zero-days already exploitedArs Technica (counts corroborated by BleepingComputer, CrowdStrike and Cybersecurity News)Stack layer / Threat patternClaude Code 2.1.265 Ships a 1 GB Tool-Result Cap and Three Prompt-Cache Reuse Fixes, Then 2.1.266 Reverts a Gateway Regression Hours LaterAnthropic (claude-code CHANGELOG)Stack layer / Threat patternblock/goose 1.50.0 deletes fast model routing and the managed model registry for local inferenceGitHubStack layer / Threat patternVibe Coding Cut Task Time 27% and Raised Security Vulnerabilities in the Same TrialarXiv 2609.09560Policy dependency / Stack layerCROSS-CATEGORY: Three Independent Agent-Action Gates Shipped in 48 Hours, All Judging the Command Against Stated IntentProduct Hunt, github.com/AGGIB/Stroq and rewarelabs.com (three independent sources; the 72% figure is Reware's own)