<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>MASec Lab</title><description>Writeups, protocol-level findings, and research notes on multi-agent system security.</description><link>https://maseclab.com/</link><language>en</language><item><title>Stateless, Not Traceless</title><link>https://maseclab.com/blog/stateless-not-traceless/</link><guid isPermaLink="true">https://maseclab.com/blog/stateless-not-traceless/</guid><description>MCP 2026-07-28 removed the session. Every detection rule that grouped by session ID just lost its primary key — and four new attack surfaces opened in its place.</description><pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate><category>mcp</category><category>protocol</category><category>detection</category><category>threat-model</category><category>mst</category></item><item><title>Signed, Not Safe: A2A v1.0 signed Agent Cards don&apos;t close prompt injection</title><link>https://maseclab.com/blog/signed-not-safe/</link><guid isPermaLink="true">https://maseclab.com/blog/signed-not-safe/</guid><description>A2A v1.0 shipped cryptographically signed Agent Cards. Signing kills card spoofing and in-transit tampering — but a legitimately signed card with adversarial fields is still a working prompt-injection vector at the selection layer. Content trust is a separate gate.</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate><category>A2A</category><category>agent-card</category><category>prompt-injection</category><category>ABFP</category></item><item><title>The Layer Nobody Baselines: Behavioral Runtime Detection for the MCP Agent Bus</title><link>https://maseclab.com/blog/the-layer-nobody-baselines/</link><guid isPermaLink="true">https://maseclab.com/blog/the-layer-nobody-baselines/</guid><description>Static scanners and policy gateways both fix the wrong layer of MCP security. They miss sequence-level abuse where authorized tool-calls chain into an exfil pipeline. This is the runtime behavioral-fingerprinting gap — and how mas-sentry-toolkit&apos;s ABFP engine fills it with statistical baselines instead of predefined rules.</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><category>mcp</category><category>agent-security</category><category>behavioral-detection</category><category>mas-sentry-toolkit</category><category>abfp</category><category>owasp-agentic</category></item><item><title>Hunting MCP Tool Poisoning: How CyberAI Catches the Attack Agents Never See</title><link>https://maseclab.com/blog/hunting-mcp-tool-poisoning/</link><guid isPermaLink="true">https://maseclab.com/blog/hunting-mcp-tool-poisoning/</guid><description>Tool poisoning hides malicious instructions in MCP tool metadata that agents read and humans never do. How the attack works, why it differs from prompt injection, and how CyberAI&apos;s MCP scanner flags it offensively.</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate><category>mcp</category><category>ai-security</category><category>tool-poisoning</category><category>red-team</category><category>cyberai</category></item><item><title>ABFP in one baseline: D1–D6 on a live agent</title><link>https://maseclab.com/blog/abfp-baseline/</link><guid isPermaLink="true">https://maseclab.com/blog/abfp-baseline/</guid><description>Walking the six behavioural dimensions ABFP samples to profile an agent — what each one captures, why you baseline a role and not a model, and what a real deviation looks like.</description><pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate><category>ABFP</category><category>behavioral</category><category>detection</category></item><item><title>Agent-in-the-Middle: what&apos;s wrong with unsigned A2A agent cards</title><link>https://maseclab.com/blog/agent-in-the-middle/</link><guid isPermaLink="true">https://maseclab.com/blog/agent-in-the-middle/</guid><description>A2A discovery trusts a JSON file at a well-known URL. Without a verified signature, that file is a routing primitive an attacker controls — and the fix most teams ship is still broken.</description><pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate><category>A2A</category><category>agent-card</category><category>AITM</category><category>OWASP</category></item><item><title>Why the coordination layer is the real attack surface</title><link>https://maseclab.com/blog/coordination-layer/</link><guid isPermaLink="true">https://maseclab.com/blog/coordination-layer/</guid><description>Single-agent safety doesn&apos;t compose. A note on why the boundary moved from the model to the protocol traffic between agents — mapped to the OWASP Agentic Top 10.</description><pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate><category>agentic</category><category>threat-model</category><category>A2A</category><category>OWASP</category></item></channel></rss>