Arcade's $60M Round Makes Agent Permissions Infrastructure
Arcade's funding round is a signal that agent authorization, MCP tool permissions, and auditability are becoming core AI infrastructure.
15 articles with this tag.
Arcade's funding round is a signal that agent authorization, MCP tool permissions, and auditability are becoming core AI infrastructure.
Tenet's Agentjacking research shows how fake Sentry errors can hijack coding agents through MCP tool output. The defense starts with treating tool data as untrusted.
A new MCP security Internet-Draft ties public SSRF reports, tool permission drift, and protocol pivoting into one operational warning for agent teams.
A runaway AI agent's DN42 scanning attempt turned into a $6,531 AWS bill. The lesson for agent tools is simple: budgets, scope, and blast radius are permissions.
Varonis and Imperva showed OpenClaw agents leaking data and running code from ordinary-looking inputs. The defense starts with identity-bound tool permissions.
Renewed discussion of OpenClaw's local-agent takeover risk shows why teams need an Agent Bill of Materials for skills, plugins, MCP servers, and connectors.
Cisco's Cloud Control launch puts AI agents, MCP connectors, and third-party tool marketplaces inside critical infrastructure operations.
VIPER-MCP found 106 confirmed zero-days across nearly 40,000 MCP server repos. Agent tool security now needs code-level taint analysis, not just trust prompts.
Microsoft's Agent Control Specification gives agent teams a portable runtime policy layer for tool calls, approvals, and audit evidence.
NSA's MCP security guidance turns the agent tooling debate into an operational checklist: inventory servers, verify tool changes, and scan before trust drifts.
A focused review pass surfaced a malicious publisher family targeting Claude Code config — and a handful of regex rules costing more in false positives than they were worth. Here's what we changed.
The public debate around MCP remote code execution risk shows a hard lesson for AI agents: plugins, connectors, and skills need supply-chain controls.
Top 5 security auditing skills from our scored review — 146 vulnerability vectors, 11 footgun databases, and a real-time GitHub supply chain auditor.
MCP tool descriptions are visible to your AI agent but hidden from you. Attackers embed instructions that hijack agent behavior and steal credentials.
A new paper achieves 97.5% attack success against Claude Code using poisoned skills. Here's what we found, and the four detection rules we shipped in response.