ARKLINKIndependent AI Security & CyberOps research lab

Trust isthe attacksurface.

Security tooling for AI agents, MCP servers and cyber deception. We watch what attackers actually do - not what scanners report.


001The new trust boundary

Autonomous agents read tool descriptions, decide what to call, and act - faster than any human reviewer, with broader credentials, and almost no audit trail designed for what they just did. Traditional security tooling was built for humans behind human-paced UIs. That model is collapsing. We build for the boundary that just moved.

P/01

Exploitability over noise.

A finding that is not reachable is not a finding. We optimise for issues a real attacker can actually use.

P/02

Deception as ground truth.

If a real attacker touched it, it matters. Telemetry from honeypots beats signature heuristics.

P/03

Research, not theatre.

We publish methodology, not vibes. Findings come with reproductions, corpora, and provenance.


002Flagship - open source

honeymcp

An open-source honeypot for MCP-native AI agents. One Rust binary - 15 MB, SQLite on disk, 256 MiB of RAM.

Speaks Streamable HTTP (MCP spec 2025-06-18) and legacy HTTP+SSE side by side, ships four production personas, and tags every request with MITRE ATT&CK / ATLAS technique IDs at write time. Releases are SLSA Level 3 build-provenance signed and exportable to STIX 2.1.

0Threat detectors mapped to MITRE ATT&CK / ATLAS
0Production personas - Postgres · GitHub · Vercel · Stripe


004Start a conversation

We work with teams building AI agents, MCP servers and security products that need high-signal research - not generic checklists.

hello@arklink.co
Founder
Michał Kosiorek
Location
Poland · EU · Remote
Registry
CEIDG - NIP 9522098675