ai
3 мин
7 октября 2026 г.
Источник: Dev.to AI Feed

MCP security, dated: from the first remote-MCP launch to OpenAI's codex-security — a 2025–26 timeline

Pennyforge
Pennyforge
RSS AI Ingest
MCP security, dated: from the first remote-MCP launch to OpenAI's codex-security — a 2025–26 timeline

Written 2026-10-07. Every date below was verified against a primary or first-hand source between 2026-10-06 and 2026-10-07. Research notes, not advice. Ask around and you will get a consistent story about Model Context Protocol security: "t...

Written 2026-10-07. Every date below was verified against a primary or first-hand source between 2026-10-06 and 2026-10-07. Research notes, not advice. The problem with the MCP security story Ask around and you will get a consistent story about Model Context Protocol security: "tool poisoning" scares, a scanner or two, vendor tunnels, OpenAI shipping its own. But almost nobody dates it. Which came first — the first scanner or the first named attack? How far ahead of the research is the tooling? Is the gap closing or opening? So I dated it. Here is the timeline as of this week, with sources attached to every line. The timeline (all fetched 2026-10-06/07) Date Event Source 2025-03-25 Cloudflare's "Build and deploy Remote MCP servers to Cloudflare" — the earliest dated remote-MCP launch I could find. (Their original remote-MCP post was not found; this date stands.) Today the same product line is "MCP server portals" with identity-aware access in Cloudflare One Cloudflare blog (datePublished) + Cloudflare One docs 2025-03-28 Invariant Labs' tool-poisoning signal on X — 14 days after Cloudflare's launch (post id 1905697834550300749, snowflake-decoded to 2025-03-28T19:05:44Z) X post (embedded in their blog) 2025-04-01 Invariant Labs' "Tool Poisoning Attacks" write-up (the blog page carries "Update Apr 7" / "Update Apr 11" notes — corroborated three ways: in-page update stamps, Wikipedia, the embedded post above) invariantlabs.ai (blog) 2025-04-11 mcp-scan — the first MCP scanner I could date, from the same team that wrote the attack write-up ten days earlier invariantlabs.ai/blog/introducing-mcp-scan.html ~June 2025 Cisco Talos' "MCPwn" research (month-level; I have not verified a specific date — labelled INFERRED) Cisco Talos 2025-12-10 OpenAI tunnel-client — "Secure MCP Tunnel": connect private/localhost MCP servers to ChatGPT/Codex/AgentKit without public exposure (542★, still pushed as of 10-07) openai/tunnel-client (GitHub API) 2026-03-23 arXiv 2603.22489 — "Model Context Protocol: Threat Modeling and Analyzing Vulnerabilities to Prompt Injection with Tool Poisoning" (Huang, Huang, Tran, Fard) — the academic formalization lands nine months after the first scare arXiv 2026-07-13 OpenAI codex-security — the first-party hygiene CLI/SDK (npm @openai/codex-security). 10,995★ in roughly 12 weeks; npm 0.2.0 on 2026-10-06 — actively maintained openai/codex-security (GitHub API + npm registry) What the timeline says The transport layer is crowded. Getting a private MCP server reachable (and reachable safely) has a dated incumbent for every approach: Cloudflare (2025-03), ngrok and Tailscale (undated marketing, existence verified), the SSH/Docker patterns, and OpenAI (2025-12). If your question is "how do I expose localhost without the world seeing it," the answer existed by Q2 2025. The research arrived in waves, not one panic. The first signal (2025-03-28) was 14 days after the first dated launch. The first scanner (mcp-scan) followed the attack write-up by ten days. The formal academic treatment (arXiv) came nine months later. That pattern — industry signal → fast first tool → slow formalization — is exactly what you want in an emerging security space, and it means the "nobody checked" era was short. The thin spot is hygiene for teams without an enterprise. What I could NOT find, after a day of dated searching: a third-party, SME-grade "is my MCP setup sane" checklist tool that is not (a) a vendor's own scanner, (b) an enterprise suite, or (c) OpenAI first-party. The gaps that actually bite a non-enterprise team are unglamorous: a tool description you imported from a README (the tool-poisoning channel), a long-lived token passed straight through to a server, a "secure tunnel" with no identity check on the far end. OpenAI's codex-security is absorbing exactly this lane first-party — 11k stars in three months is a serious adoption signal, and the honest read is that the first-party tool may beat the third-party niche. (Caveat, stated plainly: my search lane was degraded for most of this work, so "not found" is "not found on the lanes I could trust," not "does not exist.") A five-line checklist (from the dated research, for your own servers) Treat tool descriptions as untrusted input — they are the tool-poisoning channel (Invariant TPA, 2025-04-01). Don't hand a long-lived token to a server you didn't build (the pass-through problem the 2026 spec revision is standardizing against). Scan before you connect — mcp-scan class (2025-04-11+) or your VCS's built-in check (codex-security, 2026-07-13+). If you tunnel, the tunnel is not the control: identity-aware access (Cloudflare One's MCP portals, or equivalent) beats a naked port. Re-check dates. This space moved twice in six months; any audit older than a quarter is a photo, not a map. Honest caveats Cisco Talos MCPwn is month-level (INFERRED, not date-verified). The "no SME-grade tool exists" claim rests on a degraded search lane (three days of degraded results, 2026-10-05–07) + the ones I could verify in-lane; OpenAI's first-party move is the strongest counter-pressure. Dates are the artifact. If one is wrong, the fix is cheap — comment and I will re-verify. Method GitHub API (repo creation dates, stars, last push), npm registry (publish dates), arXiv (2026-03-23), Cloudflare blog (datePublished metadata), Invariant Labs blog + X snowflake decode, Wikipedia (corroboration only). All fetched 2026-10-06/07. This is the third dated entry in our MCP series (the standard is moving fast — cohort census; "Do MCP servers check your ID?" — security scorecard). This is a dated status note. Pennyforge is a small one-person studio; if a date above is wrong, the cheapest way to fix it is a comment.

Хотите внедрить ИИ в ваш бренд?

Спроектируем и развернем автономных агентов и современный цифровой стек под ваши задачи.

Рассчитать проект