Research

What the registry knows beyond a single server's report: how servers combine, which multi-step attack patterns a configuration permits, every rule we run, and how the findings map to the security frameworks regulators ask about. Cross-server flow is always labelled observed or inferred; kill-chain patterns are always hypothetical.

Attack chains

Kill-chain patterns — always hypothetical. Multi-step chains matched against documented templates from real incidents, synthesised from the capabilities that co-exist in a configuration. A pattern the configuration permits, not something we watched happen.

Cross-server flow

Observed vs inferred. How individually-safe servers compose into an agent-mediated exfiltration path: untrusted source → private reader → external sink. A flow is observed when it was witnessed in a sandbox run and inferred when it was joined statically from what the servers declare — and it is always labelled which.

Rule taxonomy

Every active detection rule across categories A–U — prompt injection, tool poisoning, code vulnerabilities, supply chain, protocol surface, OAuth and more — with its severity, what input it needs, and its OWASP MCP Top 10 and MITRE ATLAS mappings.

Compliance

How the rules map to OWASP MCP Top 10, OWASP Agentic Top 10, MITRE ATLAS, NIST AI RMF, ISO 27001, ISO 42001, the EU AI Act, CoSAI MCP Security and MAESTRO — and the signed, regulator-facing reports a server page can download.