Field notes
Notes
One post a week, on what we are actually building and finding. Every post separates what is confirmed from what we do not yet know, and names its sources with primary material first. Research is written in English, client-facing writing in Polish, and nothing is machine translated.
N/01All posts
01Two perfect tens, and neither is an AI bugThe worst two advisories of the week both sit in a product with AI in its name. One is SQL injection. The other is code injection. The only new thing about them is where they live.Act02The MCP attack surface is the transport, not the protocolFifteen advisories in ten days, and almost none of them are about Model Context Protocol itself. They are about the plumbing underneath it, and about a scoring system that cannot describe agent-shaped harm.Act03A GitHub issue is now a credential-stealing primitiveThree coding agents, three unrelated exploits, one shared mistake: the code that checked the action was not the code that performed it.Act04Two tiers of consent, or analytics that store nothingA cookie banner does not have to be a wall, and analytics do not have to start by writing an identifier to someone's device. Here is exactly how this site does it, and why.Act05What an MCP honeypot actually recordsDeception for Model Context Protocol servers is not a fake shell. It is a persona that answers plausibly, detectors that label intent, and an export format someone else's tooling can read.Watch
