POST
·
2026-04-02
·
8 min read
ECOSYSTEM DATA
91% of repos flagged by at least one of sixteen scanners. Half landed in the yellow zone — functional, maintained, and quietly carrying CVEs. The full breakdown, including which engines fire most often and which agree.
Read the report →
[ chart · 16 engines × 2,896 repos ]
POST
·
2026-03-22
·
12 min read
METHODOLOGY
A long-form essay on why the MCP ecosystem looks like npm circa 2014 — and which threat categories are unique enough to need new scanners. No vendors mentioned, no products pitched.
Read the essay →
POST
·
2026-03-06
·
9 min read
CROSS-ENGINE
We ran 16 scanners against 769 repos. They agreed on almost nothing. Co-occurrence tables, overlap diagrams, and the case for never trusting a single tool's "all clear".
Read the analysis →
POST
·
2026-02-18
·
6 min read
METHODOLOGY
Severity weights, engine weights, the per-engine cap, and the published nonlinearity. If you cannot reproduce a score on your own machine, it does not count as a verdict.
Read the spec →
POST
·
2026-01-29
·
5 min read
THREATS
Three months of YARA matches: how often MCP tool descriptions contain instruction-like language that could quietly steer an agent's next step.
Read the dispatch →
Archive · everything older
2025-12-11
First red-light: a leaked AWS key, two days early
4 MIN
→
2025-11-04
Why we picked oklch over hex (and what broke)
3 MIN
→
2025-10-22
v0.1 in a weekend: Trivy, TruffleHog, and a regex
7 MIN
→
2025-09-30
Posting on Hacker News, accidentally going front-page
5 MIN
→