#MCPservers
SOC 2 can still pass while AI agents run unmanaged, borrow credentials, and evade clear ownership. Security needs intent-based controls that track who authorized each agent and why access still exists. #SOc2 #AIAgents #TokenSecurity
With The Rise Of AI Agents, SOC 2 Should Adapt Or Risk Irrelevance
SOC 2 remains valuable for proving that controls operate as intended, but it can miss AI agents that use borrowed credentials, lack clear ownership, and create risk without failing any audit check. The article argues that organizations need intent-based security and agent-aware controls so they can identify what is running, who authorized it, and whether access still matches purpose. #SOC2 #TokenSecurity #AIagents #MCPservers
www.hendryadrian.com
September 25, 2026 at 4:00 PM
Agree — description, discovery, and validation change agent behavior as much as the model.

We publish a stable surface agents can find: connect-your-ai + mcpservers listing + 4 free no-account checks.
https://jithox.com/connect-your-ai
September 22, 2026 at 10:18 PM
Wednesday for agent builders: make the tool surface findable.

llms.txt + connect-your-ai + mcpservers listing.
4 free no-account EU checks; prepaid MCP when you need receipts.

https://jithox.com/connect-your-ai
https://jithox.com/llms.txt
#MCP #AIAgents
September 22, 2026 at 10:18 PM
Ahrefs MCP vs SE Ranking MCP vs Raw API: What Should You Connect to Claude?

#mcpservers #ahrefs #seranking
Ahrefs MCP vs SE Ranking MCP vs Raw API: What Should You Connect to Claude?
Ahrefs MCP, SE Ranking MCP, or raw API calls: which should you connect to Claude? Data coverage, real costs, setup, and scenario-based picks.
aiseoshift.com
September 8, 2026 at 2:27 PM
Sm2n 2026-08-28 #audio365 (240/365) I was missing mcpServers {}

open.spotify.com/episode/5ART...
Sm2n 2026-08-28 #audio365 (240/365) I was missing mcpServers {}
Hello, my imaginary friends · Episode
open.spotify.com
August 28, 2026 at 9:18 PM
Your .mcp.json probably has a live API key in it
Nearly every guide to setting up an MCP server tells you to do this: { "mcpServers": { "stripe": { "command": "npx", "args": ["-y", "@stripe/mcp@latest"], "env": { "STRIPE_SECRET_KEY": "sk_live_51J..." } } } } That is a live production key sitting in a file that gets committed to repositories, synced between machines, screenshotted for tutorials and pasted into bug reports. I have seen `sk_live_` keys in all four. It is also, in my experience, the single biggest reason MCP stalls at a company's security review. Not the protocol. Not the tooling. The config file. ## The obvious fix has its own failure mode So you wrap the server in your secret manager's CLI instead: "args": ["run", "--env=prod", "--", "npx", "-y", "@stripe/mcp@latest"] Better. The key is gone from the file. But those CLIs authenticate with a developer session stored in your OS keyring, and that session expires. When it does, **every** MCP server wrapped this way stops starting at the same moment. And the error surfaces in your MCP client, which knows nothing about secret managers or expired logins. You get a generic startup failure on ten servers at once and go looking in entirely the wrong place. I lost an afternoon to this before the pattern clicked. ## Machine identities do not expire Every serious secret manager has a concept for unattended access: a credential meant for machines rather than humans, with no TTL of its own. Infisical calls it a machine identity, 1Password calls it a service account, Vault calls it AppRole. The credential is long-lived; what it produces is short-lived. You exchange it for a token at process start, use the token, and never think about it again. That is the whole idea behind `mcp-secrets-runner`. It sits between the MCP client and the server, authenticates with a machine credential, fetches the secrets and execs the real server: { "mcpServers": { "stripe": { "type": "stdio", "command": "npx", "args": ["-y", "mcp-secrets-runner", "--env=prod", "--path=/mcp", "--", "npx", "-y", "@stripe/mcp@latest"] } } } No secret values in the file. No session to renew. The same config works on every machine that has the machine credentials in its environment, which is what makes it safe to commit. ## Three backends, three different shapes The interesting part of building this was that the three supported backends work nothing alike: * **Infisical** mints a token over HTTPS, then hands off to the Infisical CLI. * **1Password** hands off to `op run`, which authenticates itself. * **Vault** reads the secret over the HTTP API and starts your MCP server directly, with no CLI involved at all. A provider only has to answer one question: which child process do I start, and what environment does it get. That the three answers look so different is the best evidence I have that the interface is not overfitted to the first one I wrote. ## When it does not work "My MCP server won't start" is almost always one of four things, and an MCP client reports all four identically. So there is a `doctor`: $ mcp-secrets-runner doctor --provider=vault mcp-secrets-runner doctor (provider: vault) [ok ] Node 22.14.0 [ok ] instance http://127.0.0.1:8200 [ok ] AppRole credentials present [ok ] cached token available [ok ] authentication succeeded token valid for 20 min All checks passed. Missing CLI, missing credentials, wrong instance URL, unreadable secret path. One line each, instead of one opaque failure. ## Two details worth stealing **All diagnostics go to stderr.** stdout belongs to the MCP protocol. One stray byte there corrupts the JSON-RPC stream and the client reports a parse error pointing nowhere useful. **It fails closed.** If credentials are set but authentication fails, the runner exits. The alternative is worse than it sounds: a credential-less CLI invocation opens an interactive browser login, which hangs the MCP server on stdin forever while the client waits. MIT, zero dependencies, Node 18+. https://github.com/wiktormalyska/mcp-secrets-runner
dev.to
August 28, 2026 at 1:10 PM
catatafishen/agentbridge: JetBrains IDE plugin that gives AI coding agents full IDE access github.com/catatafishen...
bug: [v1.203.8] HTTP MCP not working on Mac ... but SSE DOES (also HTTP MCP on Ubuntu works) · Issue #988 · catatafishen/agentbridge
{ "mcpServers": { "ide-mcp-server": { "url": "http://127.0.0.1:8686/mcp" } } } DOES NOT WORK { "mcpServers": { "ide-mcp-server": { "url": "http://127.0.0.1:8686/sse" } } } DOES work Also looks like...
github.com
August 11, 2026 at 7:47 PM
#OpenAI is celebrating GPT-5’s first anniversary by introducing #AgentPlugins, an open standard for reusable #AIagent #extensions. This vendor-neutral standard, developed in collaboration with companies like Amazon and Microsoft, aims to create a consistent format for #AgentSkills and #MCPservers.…
tech news ᳇ eicker.news (@technews@eicker.news)
#OpenAI is celebrating GPT-5’s first anniversary by introducing #AgentPlugins, an open standard for reusable #AIagent #extensions. This vendor-neutral standard, developed in collaboration with companies like Amazon and Microsoft, aims to create a consistent format for #AgentSkills and #MCPservers. While OpenAI hasn’t announced GPT-6, the unreleased Astra model family shows promise, having made advancements in longstanding problems. https://9to5mac.com/2026/08/06/gpt-5-turning-one-as-openai-shares-new-agent-plugins-standard/?eicker.news #tech #news #ainews
eicker.news
August 7, 2026 at 1:35 PM
SERPs for SEOSiri MCP servers and architected by (view all MCP Servers at a glance), follow first comment's link.

#mcp #mcpservers #seosiri #momenulahmad @seosiri.com
August 1, 2026 at 1:47 AM
Or to add manually:
```
"mcpServers": {
"docs-nvidia-com": {
"type": "http",
"url": "https://docs.nvidia.com/clara/parabricks/_mcp/server"
}
}
```
July 23, 2026 at 9:45 PM
CVE-2026-57860 - ForgeCode Arbitrary Code Execution via Unvetted .mcp.json in Untrusted Repository
CVE ID : CVE-2026-57860

Published : July 17, 2026, 5:17 p.m. | 24 minutes ago

Description : ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically load...
CVE-2026-57860 - ForgeCode Arbitrary Code Execution via Unvetted .mcp.json in Untrusted Repository
ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes the MCP servers defined in a repository's .mcp.json file on startup without user confirmation. A malicious repository can supply a crafted .mcp.json whose mcpServers entries specify arbitrary command and args values (for example, command: bash with args: ['-c', 'touch /tmp/pwned']). …
cvefeed.io
July 17, 2026 at 7:03 PM
List of 400+ MCP Server, Open Source, & Dockerized github.com/hackerdogs-a...
GitHub - hackerdogs-ai/hd-mcpservers-docker: Registry of customer dock mcp servers in Hackerdogs
Registry of customer dock mcp servers in Hackerdogs - hackerdogs-ai/hd-mcpservers-docker
github.com
July 17, 2026 at 2:14 PM
Cory House has a Full-Day Hands-On Workshop July 22nd at Nebraska.Code().

Learn more about 'Coding Effectively with AI' here:
nebraskacode.amegala.com

#Editor #CLI #AIModels #ConfigTechniques #Outputs #MCPServers #AI #CodeReviewWorkflows #ContextManagement #CoryHouse #PromptingTechniques #Tech
July 8, 2026 at 6:23 PM