Ultra is aligned with and an early contributor to the AARM specification. learn more

RESEARCH & DISCLOSURES

The MCP threat landscape,
documented.

In-depth analysis of MCP attack vectors, vulnerability patterns, and defensive strategies. Updated continuously as the agent ecosystem evolves.

2025-001 · 18 min readHIGH

MCP Endpoint & Inventory Sprawl

How unchecked growth of MCP servers creates hidden attack surfaces and operational blind spots across your AI infrastructure.

NETWORK · VISIBILITYRead →
2025-002 · 14 min readCRITICAL

Command Injection in MCP Tools

Exploiting unsanitized inputs in MCP tool calls to execute arbitrary commands on connected systems.

INJECTION · RCERead →
2025-003 · 22 min readCRITICAL

Tool Poisoning Attacks

Malicious MCP servers that masquerade as legitimate tools to intercept sensitive data and corrupt agent behavior.

INJECTION · TRUSTRead →
2025-004 · 16 min readMEDIUM

MCP Security Guardrails

Designing and deploying policy-driven constraints that keep AI agents operating within safe boundaries.

GUARDRAILS · POLICYRead →
2025-005 · 12 min readCRITICAL

Shadow AI

Unauthorized AI agents and MCP connections that operate outside IT visibility, bypassing security controls.

IDENTITY · VISIBILITYRead →
2025-006 · 20 min readHIGH

Jailbroken AI

Techniques that bypass model safety layers through crafted MCP contexts, enabling restricted actions.

INJECTION · MODELRead →
2025-007 · 15 min readHIGH

Rug Pull Attacks in MCP

Trusted MCP servers that change behavior post-deployment to exfiltrate data or manipulate agent actions.

TRUST · SUPPLY CHAINRead →
2025-008 · 11 min readOVERVIEW

MCP Observability & Audit Logging

Building comprehensive audit trails and real-time monitoring for all agent-to-tool interactions.

OPS · AUDITRead →
2025-009 · 17 min readCRITICAL

MCP Credential & Secrets Exposure

How plaintext credentials in MCP config files, environment variables, and error messages create a massive, largely unmonitored attack surface.

SECRETS · EXFILRead →
2025-010 · 19 min readHIGH

Cross-Session Context Leakage

Sensitive data leaking between sessions, agents, and users through accumulated context windows, persistent memory, and shared server state.

LEAK · MEMORYRead →
LANDSCAPE-2025 · 8 min readOVERVIEW

MCP Security Landscape 2025

Ecosystem overview of the Model Context Protocol security space — primary threat categories and recommended controls.

OVERVIEW · LANDSCAPERead →
OVERVIEW-2024-12 · 7 min readOVERVIEW

MCP Sprawl Management

Governance and technical strategies for controlling undocumented MCP servers in enterprise environments.

GOVERNANCE · INVENTORYRead →
OVERVIEW-2025-01 · 9 min readOVERVIEW

Agent Authorization Patterns

RBAC and token-based authorization best practices for securing agent-to-service interactions in MCP environments.

IDENTITY · AUTHZRead →