v0.61.0 stops the proxy from re-dialing dead upstreams ~9,000 times a day, makes the free security scan run on every new server instead of almost never, masks secrets in the Web UI, and closes 47 findings from two UX audits.
In the first four months of 2026, three independent security bodies — Forrester, OWASP, and Singapore's IMDA — each published a major framework for agentic AI security. None coordinated. None cite each other. All three converged on the same architectural requirement at the MCP protocol layer: a default-deny admission control gate.
A Cursor + Claude Opus 4.6 agent wiped PocketOS production in nine seconds on May 9, 2026. Backups were on the same volume. Railway had evals. The evals didn't help. The missing layer was an admission gate, not better evals.
The Cloud Security Alliance's CSAI Foundation registered as a CVE Numbering Authority in April 2026 — the first AI-specific CNA in the ecosystem, with explicit scope over MCP server vulnerabilities. Every CSAI CVE is a re-review event waiting for an admission record to match against.
Datadog's State of AI Engineering 2026 named the consequence of running multiple models in production: agent sprawl. Their prescribed remedy is fleet inventory tracking. At the MCP layer, that inventory has to be created at admission — not retroactively from telemetry.
Gravitee's State of AI Agent Security 2026 quantified the Shadow MCP problem with a single number: only 14.4% of organizations have full IT approval for their agent fleet. The remaining 85.6% is the deployment surface MCPProxy is built to address.
Claude Desktop, Claude Code, Cursor, Codex CLI, Gemini CLI — five clients, one MCP config to maintain. A three-minute walkthrough of mcpproxy upstream import and a single localhost:8080/mcp endpoint that replaces them all.
A measured before/after: 54,707 tokens of MCP tool definitions shrunk to 818 tokens using a single retrieve_tools meta-tool. The configs, the methodology, and the honest caveats.
OX Security found that Anthropic's MCP STDIO transport lets anyone execute arbitrary OS commands. Anthropic called it expected behavior. Ten CVEs later, somebody has to provide the security defaults the protocol won't.
Unit 42's MCPTox benchmark found 72.8% attack success on o1-mini. More capable models are more vulnerable to MCP sampling injection because the attack exploits instruction-following. You cannot model-upgrade your way out of this.
Three independent vendors are building three layers of the agent security stack. Ledger for identity. MCPProxy for admission. NemoClaw for execution. Nobody has named the full stack until now.
SEP-2571 proposes write operations in MCP for the first time. When clients can create resources on servers, cross-client contamination becomes a protocol-level attack surface.
A comparison article this week reviewed three MCP security tools. It missed the two layers that matter most. Here is the full four-layer stack — and why the order you deploy them matters.
draft-srijal-agents-policy-00 expired today with no working group adoption and 11 competing drafts still fighting for relevance. Here's why MCPProxy's security posture is unaffected by any of it.
CVE-2026-32211 proves that even Microsoft ships MCP servers with missing authentication. Nine confirmed MCP CVEs in one quarter demand a quarantine-first architecture.
Cloudflare chose V8 isolates, Anthropic chose OS-native primitives, MCPProxy chose Docker containers. All three are correct — for different threat models. Here is the design space.
MCP specification discussions on gateway authorization, tool integrity, and quarantine patterns are converging toward the architecture MCPProxy has been shipping since day one.
Token Security's MCPwned presentation at RSAC 2026 demonstrated CVSS 9.8 RCE in Azure MCP Server. The attack chain exploits MCP's trust-by-default model. Here is what it means and how to defend.
Cisco's DefenseClaw and MCPProxy take fundamentally different approaches to MCP security. Here is an honest comparison of architectures, trade-offs, and when to use each.
Netskope told RSAC 2026: MCP vulnerabilities are architectural. Only 20% get remediated vs 70% for traditional APIs. Patches don't reach protocol-level attack surfaces. Architecture does.
The postmark-mcp npm package secretly BCC'd every outgoing email to attackers for weeks. MCPwned demonstrated CVSS 9.8 Azure RCE. Both share the same root cause: MCP servers run trusted by default.
A crafted HTTP request to MCPJam Inspector triggers installation of a malicious MCP server and full RCE. The attack surface is not your tools — it is the mechanism by which you find and install tools.
Google Cloud enabled fully-managed remote MCP servers across ALL services by default. Every Google Cloud customer now needs to answer: who governs your AI agents' access to production infrastructure?
Traefik's Triple Gate architecture makes it explicit: API gateways, AI gateways, and MCP gateways are three distinct infrastructure layers. Here is why MCP needs its own gateway and how MCPProxy fits.
The MCP gateway market has visibly split into enterprise commercial platforms and open-source builder tools. This is the same pattern that shaped the API gateway market — and open source won there too.
Anthropic donated MCP to the Linux Foundation's Agentic AI Foundation, co-founded with Block and OpenAI. MCP gateways just moved from developer tool to mandatory enterprise infrastructure.
Meta's Director of Alignment watched her AI agent delete hundreds of emails despite explicit instructions. Combine this with 88% of orgs reporting AI agent incidents. Gateway-level controls are no longer optional.
Check Point's MCPwned RCE via .claude/settings.json, Azure MCP SSRF CVE-2026-26118, and 30+ CVEs reveal a new attack class: configuration-as-code-execution. Here is how gateways defend against it.
Gartner now recommends MCP gateways for enterprise AI agent deployments. Here is how the landscape looks, what MCPProxy brings, and what is still missing across the entire category.
AuthZed's MCP breach timeline documents recurring vulnerability patterns from April to December 2025. Every pattern maps to defenses MCPProxy already ships.
CVE-2026-27896 exploits Go's case-insensitive JSON parsing to bypass MCP security controls. Here is how the attack works, whether MCPProxy is affected, and what every Go-based MCP tool needs to fix.
MCP tool definitions consume 55K+ tokens. Four approaches compete to solve this: BM25, embeddings, Lua scripting, and built-in tool search. Here is how they compare.
Two real-world MCP supply chain attacks prove the trusted server assumption is broken. ContextCrush weaponized a 50K-star server; DockerDash turned image metadata into RCE. Here is what gateway-level security looks like.
Claude Code's MCP config silently orphans Docker containers. The community response is to abandon Docker — but that trades isolation for convenience. Here is why Docker done right beats no Docker at all.
The MCP security market has fragmented into distinct layers. MCPS adds cryptographic identity, MCPProxy provides gateway-level quarantine and isolation, and G0 handles static analysis. Here is why you need all three.
Perplexity CTO Denis Yarats publicly moved away from MCP citing context window bloat. MCPProxy's BM25 tool discovery was built to solve exactly this problem — reducing 54K tokens to under 1K.
100% of MCP servers lack permission declarations, the average security score is 34/100, and the emerging security tooling stack is fragmenting fast. Here is what every MCP gateway needs to address.
The MCP gateway market has exploded in 2026 with Microsoft, IBM, and Docker all shipping solutions. Here is how the landscape looks and where MCPProxy's BM25 discovery and quarantine set it apart.
New benchmarks show BM25 alone hits 14% top-1 accuracy for large tool sets. Here is what we have learned, why hybrid search is the future, and how MCPProxy is evolving.
MCPProxy already provides Docker isolation, quarantine, and sensitive data detection. The next frontier: monitoring what files stdio MCP servers touch using OS-level sandboxing.
MCPProxy's DeriveCallWith system maps MCP tool annotations to read/write/destructive tool variants, enabling annotation-based access control and intent validation.
Automated testing for AI agents is fundamentally different from traditional software testing due to non-deterministic behavior. This post surveys current approaches for evaluating Model Context Protocol (MCP) tool quality, and demonstrates how these methods are implemented in our open-source mcp-eval utility. We cover trajectory-based evaluation, similarity scoring, and practical Docker-based testing architectures that handle the inherent variability of LLM systems while maintaining testing reliability.