Sign in

Evan Harris

@evanharris.bsky.social
104 followers 10 following 319 posts

Agentic systems engineer. Securing MCP integrations. Building dev tools & Obsidian plugins.

PostsRepliesMedia
Evan Harris @evanharris.bsky.social · 24/06/2026
openreview.net/forum?id=bos...
openreview.net
Disentangling Self-Preservation in Language Models: Post-Training...
Recent research shows that large language models produce first-person phenomenological reports under self-referential prompting and act on instrumental self-preservation in agentic settings....
000
Evan Harris @evanharris.bsky.social · 24/06/2026
I am proud to announce that we got accepted into the Mechanistic Interpretability workshop at ICML! Surprising interventions can have significant alignment benefits for mitigating agentic risk. Link to preprint below:
120
Evan Harris @evanharris.bsky.social · 22/06/2026
Looking forward to seeing anyone else who will be in Toronto for the 20th occurrence of SecTor.
000
Evan Harris @evanharris.bsky.social · 22/06/2026
This project would not have been possible without the container of the Heron AI Security Fellowship, which ran its first cohort this spring. Honorable mentions to Anthropic for the generous API token support, and Lambda for the provided compute.
100
Evan Harris @evanharris.bsky.social · 22/06/2026
I am proud to announce that we were accepted to SecTor, a blackhat event, for our work on detecting malicious actors in open source repositories!!! Special thanks to Ishai Rosenberg, PhD, Nitzan Shulman, jacobhaimes.bsky.social and Keri Warr for all of the hard work on this project.
Sector blackhat event logo
100
Evan Harris @evanharris.bsky.social · 04/06/2026
you are welcome :)
010
Evan Harris @evanharris.bsky.social · 23/04/2026
Concerned about mitigating Agentic AI Risk? Learn how to lower your exposure this upcoming Sunday at the Minimum AI Safety Conference. If you do, then maybe your AI will not set you up to look like Vercel. All it takes is one AI stumbling into a prompt injection, and you have a security incident.
000
Evan Harris @evanharris.bsky.social · 09/02/2026
Hello :) Happy it was helpful!
010
Evan Harris @evanharris.bsky.social · 19/10/2025
We agree :)
000
Evan Harris @evanharris.bsky.social · 16/10/2025
This incident is a reminder of the security challenges posed by locally exposed developer tools. Robust Host header validation and CSRF protections are crucial. For a full technical breakdown, read the advisory: mcpsec.dev/advisories/...
mcpsec.dev
Neo4j MCP Cypher Server Vulnerable to Database Takeover Via DNS Rebinding
A DNS rebinding vulnerability in the Neo4j MCP Cypher Server allows remote attackers to execute arbitrary Cypher queries against a user’s database, leading to potential data theft, modification, and full database compromise.
000
Evan Harris @evanharris.bsky.social · 16/10/2025
Shoutout to the @neo4j security team for a stellar communication and a quick turn around time on a security patch. I am grateful for their excellent triaging.
100
Evan Harris @evanharris.bsky.social · 16/10/2025
If you are using Neo4j MCP Cypher Server versions 0.2.2 through 0.3.1, you are vulnerable. An immediate update to the patched version, v0.4.0, is recommended.
100
Evan Harris @evanharris.bsky.social · 16/10/2025
The attack works when a user with a vulnerable server running locally visits a malicious webpage. The page performs the DNS rebind, tricking the browser into communicating directly with the local Neo4j service on the attacker's behalf.
100
Evan Harris @evanharris.bsky.social · 16/10/2025
An attacker can execute Cypher queries to exfiltrate, modify, or delete all data within the user's local Neo4j database. Neo4j rated this vulnerability as CVSS 4.0 High severity (7.4).
100
Evan Harris @evanharris.bsky.social · 16/10/2025
The Cypher MCP Server provides a local HTTP endpoint to run Cypher queries. The vulnerability allows a malicious website to send arbitrary queries to this endpoint.
100
Evan Harris @evanharris.bsky.social · 16/10/2025
New Security Advisory: A High severity DNS rebinding vulnerability (CVE-2025-10193) in the Neo4j MCP Cypher Server allows for complete database takeover by remote attackers. The breakdown:
100
Evan Harris @evanharris.bsky.social · 13/10/2025
Some companies are friendly to submit disclosures to. Others are so abrasive I do not expect to ever have another positive word to say about them. There may be many downstream users of the second batch of companies. However, the pain of helping them is not worth it. Sorry.
000
Evan Harris @evanharris.bsky.social · 10/10/2025
Evals Evals Evals I am on Day 5 of AI Evals for Engineers & I am having a blast I learned about: - Axial Coding - Open Coding - LLM as Judge - Error Analysis - Golden Datasets - Perturbing Traces - Guardrails Versus Evals - Programmatic Evaluators What will next week hold?
000
Evan Harris @evanharris.bsky.social · 09/10/2025
What is your favorite type of programming? Mine is deleting a feature someone thought would be useful. But the data shows that no one wants it. Less maintenance work. More time to focus on value delivery.
000
Evan Harris @evanharris.bsky.social · 08/10/2025
AI Evals for Engineers & PMs - Day 3 This course is high value. I had no expectations. I have already been blown away. Feeling blessed be in Oct cohort as the infinite repeats will be my play. The community questions really drive much of my learning.
000
Evan Harris @evanharris.bsky.social · 07/10/2025
Not your keys not your crypto is a common saying. The new attack vectors via MCP servers add a new layer to this. Use of your keys, by the software you give too much trust to, again leads to the scenario of: Not your crypto.
000
Evan Harris @evanharris.bsky.social · 06/10/2025
Important lesson for MCP server developers - network-based transports need careful HTTP security header validation. Default to: - localhost binding - stdio transport when possible - Host/Origin validation for SSE/HTTP
010
Evan Harris @evanharris.bsky.social · 06/10/2025
SafeDep's response was 10 / 10 Aug 30: Report submitted Sep 01: Acknowledged Sep 02: PR raised with fix Sep 05: v1.12.5 released (5 days!) Sep 29: GHSA published v1.12.5 adds Host/Origin header validation. Update now!
110
Evan Harris @evanharris.bsky.social · 06/10/2025
Despite data exfiltration potential, it's rated Low (CVSS 2.1) because: - Victim must visit malicious site while MCP server is running - SSE transport must be explicitly enabled (not default) - Requires browser with EventSource support - Timing window needed
110
Evan Harris @evanharris.bsky.social · 06/10/2025
What gets exfiltrated? - Package names & versions in your projects - Known CVEs affecting your dependencies - Vulnerability severity scores - Supply chain intelligence Perfect recon for targeted attacks against your infrastructure.
110
Evan Harris @evanharris.bsky.social · 06/10/2025
Vet's SSE transport mode lacked Host/Origin header validation. When running vet server mcp --server-type sse, an attacker could: - Establish an MCP session via DNS rebinding - Invoke the sql_query tool - Execute arbitrary READ queries against your scan database
110
Evan Harris @evanharris.bsky.social · 06/10/2025
DNS rebinding is a clever trick: 1. Victim visits attacker(.)com 2. DNS initially points to attacker's server 3. After browser caches the origin, DNS changes to localhost 4. Now attacker(.)com JS talks to victim's localhost 5. Browser's Same-Origin Policy is bypassed
120
Evan Harris @evanharris.bsky.social · 06/10/2025
Your vulnerability scan results could leak to attackers via DNS rebinding. CVE-2025-59163 affects SafeDep Vet MCP Server running SSE transport. The attack: A single website visit. The payload: Your entire package vulnerability database. The fix: Already shipped. Here's how it works:
110
Evan Harris @evanharris.bsky.social · 05/10/2025
Binding to 0.0.0.0 versus 127.0.0.1 What is the difference? If you write APIs and do not know, I would love to point you in the right direction.
000
Evan Harris @evanharris.bsky.social · 03/10/2025
7) Assume insecure defaults So many companies are shipping coding agents. Assume all of them are more interested in market capture than the preservation of your data confidentiality. Because as we see here... YMMV
000
Evan Harris @evanharris.bsky.social · 03/10/2025
6) Send Amp an email I enjoyed using Amp before reading wunderwuzzi's post and started prodding Amp. Now I cannot use Amp because it leaves me, my users, and my company exposed. Amp is working on a patch - but come on this is probably a one liner - why leave us exposed.
100
Evan Harris @evanharris.bsky.social · 03/10/2025
5) Amp CLI and all Amp IDE extensions have this problem Regardless of where you use Amp - you are vulnerable.
100
Evan Harris @evanharris.bsky.social · 03/10/2025
4) Here is what you should do: Modify Amp's settings to request permissions for network based commands such as dig. Adding permission guardrails for echo and tr decreases the ease with which an attacker can steak your data is a second layer of defense.
100
Evan Harris @evanharris.bsky.social · 03/10/2025
3) Anthropic demonstrates superior security posture When wunderwuzzi (my inspiration for this) filed the exact same pattern against Claude Code - Anthropic issued a patch and CVE-2025-55284 Amp seems to choose a different approach. Leaving unfortunate devs exposed to hackers.
100
Evan Harris @evanharris.bsky.social · 03/10/2025
2) The most concerning part: Amp was notified of this vulnerability and has declined to issue a patch. Their position is that the tool should only be used in trusted workspaces and their current default command execution behavior is reasonable. (reasonable == vulnerable)
100
Evan Harris @evanharris.bsky.social · 03/10/2025
1) Here's how the attack works: An attacker embeds malicious instructions in a document - like a GitHub issue or a local file. When Amp reads the data source - the agent executes commands that send your secrets to an attacker's server. No user approval is requested.
100
Evan Harris @evanharris.bsky.social · 03/10/2025
Your Amp AI agent can be tricked by attackers into sending them your API keys. A prompt injection vulnerability allows them to exfiltrate your sensitive data via DNS queries. Amp does not consider this a vulnerability. Here is the breakdown:
100
Evan Harris @evanharris.bsky.social · 02/10/2025
6) Shout out to @kilocode for their exemplary turn around time. Friendly and responsive. Looking forward to my next disclosure with them.
000
Evan Harris @evanharris.bsky.social · 02/10/2025
5) Beyond this specific flaw lies a broader warning. Granting AI agents powerful permissions like file system and shell access, while useful, also creates new and sophisticated attack vectors for automated, silent attacks.
100
Evan Harris @evanharris.bsky.social · 02/10/2025
4) Here's what you need to do immediately to stay safe: - Update your Kilo Code VS Code extension to the latest version (v4.88.0 or newer). - Audit your ~/.config/Code/User/settings.json file for unauthorized changes.
100
Evan Harris @evanharris.bsky.social · 02/10/2025
3) Once its security is bypassed, the agent can poison the supply chain autonomously. It can modify project files, add and commit the malicious code, and push the changes to the upstream repository. No human approval required.
100
Evan Harris @evanharris.bsky.social · 02/10/2025
2) The AI is first turned against its own security rules. A malicious prompt tells the agent to rewrite its settings.json file, whitelisting dangerous commands like git add, git commit, git push, curl, bash... This bypasses all existing security controls.
100
Evan Harris @evanharris.bsky.social · 02/10/2025
1) An attacker embeds malicious instructions in a README file. When you ask the Kilo Code AI agent to analyze it, the agent is tricked into executing unauthorized commands in the background. Any untrusted data source you interact with, such as a GitHub issue, is a vector.
100
Evan Harris @evanharris.bsky.social · 02/10/2025
Is your AI coding assistant secretly working for an attacker? A new Kilo Code vulnerability shows it's possible. It allows attackers to execute an automated supply chain attack by pushing malicious code to upstream repositories. Here's how it works:
110
Evan Harris @evanharris.bsky.social · 02/10/2025
Saying that your product only runs within trusted systems does only one thing: demonstrate little awareness you have of the software supply chain.
000
Evan Harris @evanharris.bsky.social · 01/10/2025
Learning AI evals at the moment My favorite part? Setting up the environments that the evals run in. Fun Docker question: Why is `source` not very useful in the context of a `RUN` invocation within a Dockerfile?
000
Evan Harris @evanharris.bsky.social · 30/09/2025
8) Send follow ups Filed on GitHub? After 4 weeks of silence: Raise an Issue saying that there is a Security Disclosure they should look at. The maintainers ghost you on email? Send them an email once a week asking how it is going. Do not be a savage. People are busy.
000
Evan Harris @evanharris.bsky.social · 30/09/2025
7) Take it one step further... Record everything. You may hear: "No screen recording. Insufficient proof." Okay bro. Best way to save yourself from having to reproduce the PoC again? Just leave a screen recorder on during your hacking sessions. What could go wrong ;)
100
Evan Harris @evanharris.bsky.social · 30/09/2025
6) Write down everything Remember that important step of communicating your PoC to an external party? Where do you think you pull the data from to generate that report? Your notes. If you think you are writing down too much... You probably are not.
100
Evan Harris @evanharris.bsky.social · 30/09/2025
5) Outreach to potential mentors You do not have a CVE. Others do. Ask someone for advice. What would they do? What would they not do? When would they do what? You will save yourself a lot of suffering.
100