All MCP security reports
Every attack that made MCP headlines runs through traffic like yours. The published research on MCP server security, and the Spanly scanner that detects each issue in your manifest and live traffic.
Flags tool results, resource bodies, and prompt messages carrying ANSI concealment, clear-screen, or cursor codes before they reach agent context, whether fetched live or relayed from stored data.
Catches the pivot as it fires: a read or fetch tool returns content carrying an imperative or embedded shell snippet, and the same session immediately follows with an exec, write, or delete call.
Compares every manifest against its approved baseline and flags tools whose titles, descriptions, or parameters were rewritten after the fact, escalating when the new text also trips a content check.
Probes OAuth-protected endpoints without credentials and flags any that still answer initialize, tools/list, or tools/call, so an auth regression is caught before an attacker finds it.
Traces taint across a session: when a sensitive value returned by one tool reappears verbatim in the arguments of a later outbound call, the session is flagged as an incident with the evidence attached.
Detects content a human reviewer will not see but the model will: zero-width characters, Unicode tag and bidi-override sequences, HTML comments, and base64 blobs smuggled into tool metadata.
Looking for how Spanly handles your own telemetry? See Security at Spanly. To report a vulnerability in Spanly itself, email security@spanly.com.