MCP and Agent Skills Become New Attack Surface: Permission Governance, Static Scanning and ChainDrop Injection into Claude Configuration
In August 2026, the ChainDrop worm achieved persistence by injecting into `.claude/settings.json` and `.vscode/tasks.json`, with malicious execution triggered once developers opened the repository. Meanwhile, approximately 36% of MCP servers and Agent Skills have security flaws, and 80% of enterprises lack governance for Agentic AI. This article sorts out the three-layer attack surface of models/instructions/Harness, MCP Tool Poisoning and protocol approval gaps, introduces JFrog Agent Guard and skill-audit-mcp static scanning, and provides an actionable protection checklist for CI integration and runtime approval.
Read MoreStriking 40k Stars on GitHub: AI Agent is Redefining Penetration Testing Workflows
In July 2026, the open-source AI penetration testing tool Strix (usestrix/strix) gained approximately 42,000 stars on GitHub, with a weekly increase of about 7,000, topping the monthly AI popular repository list. Strix adopts a multi-agent architecture to dynamically test applications and generate PoC exploits, supports three scanning modes: quick/standard/deep, and can be integrated into CI/CD pipelines such as GitHub Actions. Based on official documentation and public materials, this paper sorts out the capability boundaries, architectural ideas, local onboarding steps and DevSecOps integration methods of Strix, and discusses the positioning differences between Agentic security testing and traditional SAST.
Read More