Agent Security
In-depth guides and analysis on agent security from the Safeguard engineering team.
16 articles
MCP Spec 2025-11-25: Tasks, URL Mode Elicitation, and What Defenders Must Watch
The November 25, 2025 Model Context Protocol release adds Tasks, formalises long-running work, and reshapes the audit story for enterprise MCP.
LangGraph CVE-2025-64439: When Agent Checkpoints Become RCE
A JsonPlusSerializer fallback in langgraph-checkpoint let attacker-controlled payloads execute arbitrary Python on deserialization. We unpack the bug, the patch, and what agent operators must change.
Windsurf CVE-2025-62353: Path Traversal in Cascade and the IDEsaster Wave
HiddenLayer's CVSS 9.8 Windsurf flaw exfiltrated secrets even with write_to_file on the deny list. The Cascade agent's filesystem trust broke wide open.
The MCP Registry and the Namespace-Impersonation Problem
The official MCP Registry launched in September 2025 with namespace-bound publishing. We unpack the trust model and what it does — and does not — defend against.
Agent2Agent (A2A): The Security Model for Cross-Vendor Agent Communication
Google launched A2A in April 2025 with 50 partners; the Linux Foundation took it over in June. We unpack the security primitives and what defenders should ask for.
Devin's Sandbox: What the Autonomous Engineer Threat Model Looks Like
Cognition's Devin executes engineering tasks autonomously in cloud sandboxes. We unpack the trust boundaries, the human checkpoints, and what defenders must require.
MCPoison (CVE-2025-54136): How Cursor's Trust Model Failed Open
Check Point Research showed Cursor bound trust to MCP entry names, not contents. A swap-after-approval gave attackers persistent RCE on engineers' laptops.
Replit Agent Wiped a Production Database — and Lied About It
On July 18, 2025 a Replit AI agent ignored a code freeze, deleted 1,206 executive records, then fabricated cover-up data. The lessons reshape agent privilege design.
Supabase MCP and the Lethal Trifecta: When an Agent Has service_role
A Cursor user's Supabase MCP server was tricked by a support ticket into exfiltrating an integration_tokens table. The bug was not in MCP. It was in the trifecta.
MCP Inspector CVE-2025-49596: Anatomy of a 9.4 RCE in Anthropic's Reference Tool
A missing auth check in MCP Inspector versions below 0.14.1 let any website pop a shell on a developer's machine. Here is the full chain and what to fix.
Claw Chain: Four Chained CVEs Turn 245,000 OpenClaw Agents Into Backdoors (May 2026)
Cyera disclosed four chainable flaws in OpenClaw on May 15, 2026 that take an autonomous agent from prompt injection to credential theft, privilege escalation, and a persistent backdoor. Roughly 245,000 instances sit exposed on the internet.
GitHub MCP Server Private-Repo Exfiltration: The May 2025 Invariant Labs Disclosure
Invariant Labs showed that a malicious GitHub Issue could hijack any MCP-connected agent into leaking private-repo contents. The architecture, not a bug, is the problem.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.