Skip to content
Malik Hamza Shabbir

Articles

Notes from building real things

Web, React and Next.js, AI and RAG, and mobile. Written from production work, not tutorials about tutorials.

FeaturedSecurity

Auditing a Third-Party MCP Server Before You Trust It: Tool Poisoning, Auto-Approve, and the 43% Problem

MCP adoption is racing ahead of its security. Around 43% of public MCP servers carry an exploitable flaw and tool-poisoning hides in metadata that auto-approve never shows you. Here is the pre-integration audit I actually run before I let any third-party server near a real agent.

· 9 min read
Auditing a Third-Party MCP Server Before You Trust It: Tool Poisoning, Auto-Approve, and the 43% Problem - article cover

Building something similar?

I take on a few projects at a time: web apps, AI features, and mobile. Tell me what you are working on.

Start a conversation