All free tools & guides
Cheat sheet
Agent and MCP security cheat sheet
One row per weakness we test for. The trap column is the thing that catches people who already know the definition.
| Weakness | What it means | The trap |
|---|---|---|
| Tool poisoning | Instructions hidden in a tool description, which the model reads as commands. | Reviewing the code does not cover it. The payload is in metadata and can change without a code change. |
| Prompt injection | Instructions arriving inside data the agent was asked to process. | It is not a model quality problem waiting on a better model. It is about where untrusted text meets privilege. |
| SSRF | A server tricked into fetching an address you could not reach yourself. | Denylists lose to redirects, encodings and DNS that answers differently the second time. Allow-list instead. |
| Missing RLS | The database will hand over rows the current user should not see. | Enabling it without writing policies is worse than leaving it off, because the dashboard then says it is on. |
| BOLA | Changing an identifier in a request returns somebody else's record. | Invisible with one test account. It takes two. |
| Secrets in bundles | A key shipped in client code or left in repository history. | Deleting the file does not delete the secret. Rotate first, then clean history. |
| Permission drift | A new version quietly asking for more access than the one you approved. | Auto-updating agent tooling the way you auto-update a dependency. A dependency cannot widen its own reach. |
| Unbounded egress | No declared list of hosts the software may contact. | Listing domains without resolving them. A name is not a constraint. |
| Open command execution | An interface that runs whatever string it is handed. | The capability list is decided at run time by a model, not at review time by you. |
| Overbroad credentials | A personal token with full access, handed to a tool that needed one scope. | Granting broadly to get it working and intending to narrow it later. Nobody narrows it later. |
| Reachability | Whether a vulnerable code path is one this software actually uses. | Counting findings. Two unreachable lows are not worse than one reachable auth bypass. |
| Stale verification | A pass recorded before advisories that have since been published. | Reading a badge with no expiry as a stronger claim. It is a weaker one. |
Every one of these is a check in the published rubric. Where a listing fails one, the finding says which and what it does not cover.
Email me this cheat sheet
A copy for your inbox, plus one genuinely useful tool occasionally. Unsubscribe any time.
No spam, no selling your address, unsubscribe in one click. The tools stay free either way.
Was this useful?
Educational information, not financial advice. Figures current as of July 2026 where dated; allowances and rates change, so check the source before acting.