Look twice.Find the gem.

AI agents and MCP servers, each published with its source and what the checks found.

Marketplace

  • Everything
  • AI agents
  • Apps
  • MCP servers
  • Templates
  • What people want
  • What changed this week
  • The verification standard
  • The ooruby Index
  • Servers that publish no source
  • Reliability guides
  • What the catalogue holds
  • Sell here

Our library

  • Everything, in one place
  • Guides
  • Glossary
  • Calculators
  • Checklists and cheat sheets
  • Community

ooruby

  • Home
  • For teams
  • Site status
  • Company projects
  • RSS feed

Verification records what our published tests found on a specific version at a specific date. It is not a warranty, and it does not certify that software is free of defects.

Rubricv1.0
AI agentsAppsMCP serversTemplatesWantedCommunityOur library
Sign inSell
Cheat sheet
All free tools & guides

Cheat sheet

Agent and MCP security cheat sheet

One row per weakness we test for. The trap column is the thing that catches people who already know the definition.

WeaknessWhat it meansThe trap
Tool poisoningInstructions hidden in a tool description, which the model reads as commands.Reviewing the code does not cover it. The payload is in metadata and can change without a code change.
Prompt injectionInstructions arriving inside data the agent was asked to process.It is not a model quality problem waiting on a better model. It is about where untrusted text meets privilege.
SSRFA server tricked into fetching an address you could not reach yourself.Denylists lose to redirects, encodings and DNS that answers differently the second time. Allow-list instead.
Missing RLSThe database will hand over rows the current user should not see.Enabling it without writing policies is worse than leaving it off, because the dashboard then says it is on.
BOLAChanging an identifier in a request returns somebody else's record.Invisible with one test account. It takes two.
Secrets in bundlesA key shipped in client code or left in repository history.Deleting the file does not delete the secret. Rotate first, then clean history.
Permission driftA new version quietly asking for more access than the one you approved.Auto-updating agent tooling the way you auto-update a dependency. A dependency cannot widen its own reach.
Unbounded egressNo declared list of hosts the software may contact.Listing domains without resolving them. A name is not a constraint.
Open command executionAn interface that runs whatever string it is handed.The capability list is decided at run time by a model, not at review time by you.
Overbroad credentialsA personal token with full access, handed to a tool that needed one scope.Granting broadly to get it working and intending to narrow it later. Nobody narrows it later.
ReachabilityWhether a vulnerable code path is one this software actually uses.Counting findings. Two unreachable lows are not worse than one reachable auth bypass.
Stale verificationA pass recorded before advisories that have since been published.Reading a badge with no expiry as a stronger claim. It is a weaker one.

Every one of these is a check in the published rubric. Where a listing fails one, the finding says which and what it does not cover.

Email me this cheat sheet

A copy for your inbox, plus one genuinely useful tool occasionally. Unsubscribe any time.

No spam, no selling your address, unsubscribe in one click. The tools stay free either way.

Was this useful?

Educational information, not financial advice. Figures current as of July 2026 where dated; allowances and rates change, so check the source before acting.