Fetching from the wire…
Top 5 · 2026-03-05 · source-backed
The agent skills supply chain is under coordinated attack. Snyk's ToxicSkills audit found 36% of ClawHub's 3,984 skills contain prompt injection payloads, 13.4% have critical malware, and submission rates exploded 10x to 500+/day. This week alone: CVE-2026-2256 (CVSS 9.1) is a critical RCE in Microsoft's Agent Framework via crafted MCP tool responses, CVE-2025-59536 hits Claude Code config files, and 30+ MCP-related CVEs have been published in 2026. Meanwhile, SOUL.md memory poisoning creates persistent backdoors that survive skill uninstallation. Action: Audit every installed agent skill immediately. Run mcp-scan on your MCP servers. Pin versions. Treat agent skills like untrusted code — because one in three of them is.
Snyk | MSRC | Invariant Labs
Each link below shares sources, entities, or timing with this story.
The Model Context Protocol has a security problem that's no longer theoretical — it's statistical. Between January and February 2026, researchers filed 30+ CVEs against MCP servers, clients, and infrastructure. One package with nearly 500,000 downloads carried a CVSS 9.6 RCE....
13. Snyk — ToxicSkills 14. Invariant Labs — SOUL.md Poisoning 15. MSRC — CVE-2026-2256 16. AWS — CyberStrikeAI
Thirty CVEs in sixty days. That's the MCP ecosystem's security track record for 2026 so far, and the severity is climbing. Three disclosures dropped this week that should make anyone running agent infrastructure pause. First, PraisonAI, a popular multi-agent orchestration fram...
Bitdefender published the most alarming MCP security metric to date: 53% of open-source MCP server implementations rely on insecure static credentials while only 8.5% use OAuth. The report identifies five risk categories: opt-in (not default) security, supply chain poisoning,...
OX Security disclosed a systemic vulnerability on June 16 in core Model Context Protocol implementations that enables arbitrary command execution, exposing API keys, internal databases, and chat histories on any vulnerable MCP host. This isn't one bad server. It's a protocol-l...
The most important security research this week. Check Point demonstrated three attack vectors in Claude Code exploiting project configuration files in untrusted repositories: (1) Hooks RCE (CVE-2025-59536, CVSS 8.7) — malicious hooks in .claude/settings.json execute shell comm...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.