Fetching from the wire…
Public story · 2026-02-23 · source-backed
The first security tool specifically for Google's Agent-to-Agent protocol. Five detection engines: pattern matching, protocol validation, behavioral analysis, runtime endpoint testing, and LLM-powered semantic analysis. Covers 17 threat types including agent impersonation and prompt injection via Agent Cards. MIT licensed.
Ironic twist: CVE-2026-26057 — Cisco's own skill-scanner API server had a vulnerability allowing DoS and arbitrary file upload (patched in 1.0.2). The "who watches the watchmen" problem is real.
Source: Cisco Blog | GitHub
Each link below shares sources, entities, or timing with this story.
Forrest Chang's andrej-karpathy-skills repo is a single CLAUDE.md file distilling Karpathy's observations on LLM coding pitfalls. It topped GitHub trending with +44K weekly stars. Then the ecosystem detonated. Ten-plus related repos trended simultaneously with 70K+ combined st...
Three separate Anthropic changes over about two weeks point the same direction, and none of them announced themselves as a strategy. Claude Code 2.1.238 added claude self-hosted-runner --defer-shutdown-max-min, which keeps serving attached sessions on SIGTERM, parks whatever's...
The evidence list is what makes this different from the usual "they copied us" post. Minitap published on September 11 alleging Google's Artemis mobile-automation project incorporated code from Minitap's open-source mobile-use project and then stripped attribution. What they p...
The 2026 State of AI Security Report from Cisco ships real tools, not just analysis: an MCP scanner, an A2A protocol scanner, a pickle format fuzzer, and a skill file scanner — all open-source. The data behind it: 83% of organizations plan agentic AI deployment but only 29% fe...
Static binary, no runtime dependencies, cost-aware routing across many LLM providers with automatic failover, MCP client support, BYOK and self-updating, installed via curl pipe. (GitHub) Flagging the license because it's easy to miss: despite the open repo and GitHub-hosted R...
Three scanning engines: YARA rules, LLM-as-a-judge, and Cisco AI Defense inspect. New behavioral code threat analysis tracks untrusted data across functions. Also includes production readiness scanning. Enterprise-grade answer to the MCP security crisis. (GitHub)
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.