#mcp
- The [model-dependent] Caveat, Measured
My MCP audits proved a malicious instruction reaches the agent. They never checked whether it obeys. So I measured it across thirteen models.
- Auditing MCP Servers with an AI on a Short Leash
The methodology behind my MSc dissertation: depth-first security audits of MCP servers, using an LLM as an instrument I'm not allowed to trust.