Blog

Technical writing from The Hermetic Project

MCP Security Is Broken

Three MCP CVEs and a major breach in one week. The protocol was designed for capability, not containment. Here's the pattern that keeps breaking — and how credential isolation fixes it.

April 21, 2026
securitymcpcvecredential-isolationai-agents

MCPwn Is What Happens When MCP Has No Security Boundary

CVE-2026-33032 gave attackers full Nginx server takeover via an unauthenticated MCP endpoint. Here's how Hermetic's architecture prevents every step of the attack.

April 19, 2026
securitymcpcveai-agentscredential-isolation

I Played GitHub's AI Agent Security Game. Here's What Every Level Teaches About Credential Isolation.

GitHub released a game where developers hack AI agents. I played all 5 levels and mapped every vulnerability against Hermetic's architecture. Result: 5/5 prevented.

April 15, 2026
securitymcpowaspai-agents