Co-Founder of @InvariantLabsAI, PhD student at ETH Zurich. I care about security and reliability of AI systems. @[email protected]marcfischer.at Zurich, SwitzerlandJoined March 2010
Oh wow, more AI malware (uses Claude Code to search for credentials).
Is this the exponential takeoff moment people kept mentioning?
snyk.io/blog/weaponizi…
💙 Big congrats and thanks to the whole team for this small but meaningful milestone.
mcp-scan all your servers today and discover all the lethal trifectas near you.
Repo: github.com/invariantlabs-…
Great post by @liran_tal@kwhuszcza@marc_r_fischer about the recent JIRA MCP 0-click and how mcp-scan helps you identify similar issues.
Since 0.3.5 we now include built-in tools in security scanning. Toxic flow analysis in action.
labs.snyk.io/resources/curs…
I gave a talk on Wednesday at the Bay Area AI Security Meetup about prompt injection, MCP security and the lethal trifecta. Here are the annotated slides from my presentation, including notes on my weird hobby of trying to coin or amplify new terms of art simonwillison.net/2025/Aug/9/bay…
😈 BEWARE: Claude 4 + GitHub MCP will leak your private GitHub repositories, no questions asked.
We discovered a new attack on agents using GitHub’s official MCP server, which can be exploited by attackers to access your private repositories.
creds to @marco_milanta
(1/n) 👇
One of our engineers, Hemang, has created this nice example repo of an MCP Streamable HTTP implementation.
This is where things are heading for MCP, post SSE.
We are also adding support to Gateway right now.
github.com/invariantlabs-…
We recently shipped a lot of updates to mcp-scan:
- whitelisting of tools
- Improvements to the server (reducing false-positives, improving detection)
- run via npm/npx
Much more coming soon!
github.com/invariantlabs-…#mcp
I think Simon raises an important point here. LLM and agent security cannot be solved by a simpler classifier.
Instead, Guardrails focuses on detecting guardrail violations on a behavioral level. It analyzes the data flow and active agent context, to make sure, that even if a…
I think Simon raises an important point here. LLM and agent security cannot be solved by a simpler classifier.
Instead, Guardrails focuses on detecting guardrail violations on a behavioral level. It analyzes the data flow and active agent context, to make sure, that even if a…
4/ How to safeguard?
- Make sure only trusted MCP servers are being downloaded and used
- Keep minimal funds in your crypto wallet MCP
- Allow minimal access for MCP actions
- Use MCP-Scan
4/ How to safeguard?
- Make sure only trusted MCP servers are being downloaded and used
- Keep minimal funds in your crypto wallet MCP
- Allow minimal access for MCP actions
- Use MCP-Scan
After covering MCP vulnerabilities over the last few days, today, we are launching MCP-scan, a security scanner to detect MCP attacks.
Run it now: uvx mcp-scan@latest
🧵
🚀🔒 We created a security scanner to detect MCP attacks. Please check it out, and give feedback.
* Supports Claude, Cursor, Windsurf
• Checks for tool poisoning
• Checks for rug pull (tool hashing)
• Detects cross-origin violations (shadowing)
uvx mcp-scan@latest
🛡️Thoughts on the MCP vulnerability and why it's not an easy fix (1/n)
To stay updated about agent security, please follow and sign up for early access to Invariant below.
We have been working on this problem for years (at Invariant and in research).
invariantlabs.ai/guardrails
3K Followers 3K FollowingTech journalist and editor. Currently contributing to @InfoWorld @CIOonline @TheLeadDev @thenewstack. Editor of @NordicAPIs, an API blog. 👨he/him.
205K Followers 5K FollowingVC at @MenloVentures. Formerly founding team @glean, @Google Search. @Cornell CS. Tweets about tech, immigration, India, fitness and search.
20K Followers 4K FollowingTweets along my startup journey. Follow me for tips on building, selling, and raising. ceo @getthera | @ycombinator | @amazon
2K Followers 7K FollowingLLM Arch Assoc Director @Accenture Ph.D. @LTIatCMU. Past @GoogleAI Sharing insights about AI research, LLMs, multimodal AI, coding & tech. 🚀 Views are my own
2K Followers 2K FollowingDeep state enthusiast @cambridge_cl. Previously built @aisecurityinst, AI Safety Summit, UK AI Research Resource, EU GPAI Code of Practice.
59K Followers 133 FollowingWe make tinygrad and sell tinybox, the best perf/$ AI computer.
$25k for 4x 5090 in a quiet box.
Our mission is to commoditize the petaflop.
193 Followers 1K FollowingPh.D. Student in CS @UnivManchester | MSc in CS & AI @UnivNottingham | Exploring Neuro-Symbolic Models in NLI for Clinical Applications
212 Followers 230 FollowingDoctoral Researcher specializing in "Machine Learning and Computational Biology" at TUM & Helmholtz, part of @fabian_theis research group
10K Followers 4K Followingsth new // ex Gemini RL+Inference @GoogleDeepMind // Chat AI @Meta // RL Agents @EA // ML+Information Theory @MIT+@Harvard+@GeorgiaTech // زن زندگی آزادی
12K Followers 239 FollowingIn the golden age of machine learning we're bringing hackathon life back to Silicon Valley! Shaping the future of AI, one line of code at a time.
No recent Favorites. New Favorites will appear here.