2026-10-11 16:38 UTC

SkillProof claims its published adversarial tests fail four of five pinned official MCP server versions, including SSRF, read-only transaction escape, and arbitrary file-write findings, potentially requiring stronger deployment boundaries than official provenance alone provides.

state: corroboratedheat: lowuncertainty: mediumconvergesscott: mediumagentic-security mcp supply-chain-securitySkillProofroblambert9

What is this?

SkillProof (GitHub user roblambert9) publishes adversarial behavioral verifications of pinned versions of the official MCP reference servers, claiming four of five fail — SSRF in fetch via 302 redirect to loopback, a read-only transaction escape in postgres, an arbitrary file write in sqlite via VACUUM INTO, and a dangling-reference integrity defect in memory, with filesystem passing — shipped as signed Ed25519 'Trust Manifests' with a standalone re-run harness; one verdict (fetch) was publicly downgraded after a harness bug, and the publisher also sells paid verification tiers. An independent diff audit claiming 140 silent changes across all 66 official MCP server release pairs supports the broader thesis that a version pin plus official provenance does not predict behavior. The supplied coverage strongly corroborates that MCP servers are an operational 2026 attack surface in general — active-exploitation CVEs in mcp-atlassian, ~half of 33K scanned builds flagged, large scans reporting ~33% critical, the postmark-mcp supply-chain incident — but none of it verifies SkillProof's specific findings, and coverage of SkillProof itself is nearly absent: the only direct hit is a social post citing a different count (3-of-4 vs the claimed 4-of-5).

Why it matters to Scott

Two methodologically distinct external lines — SkillProof's pinned-version adversarial failures and the independent 140-silent-diffs audit — supply dated supporting evidence for exactly the position Scott's canon holds: 'Provenance Is Not Trust' plus the MCP Tool Belt's requirement for a security boundary outside the protocol, and SkillProof's signed, version-pinned Trust Manifests structurally mirror his version-bound AI assessment practice. It is actionable on his own surface (which official MCP servers and versions the production IP Wiki connector and the Bedrock docs-server proxy actually run), but the exploit findings remain unreproduced single-publisher claims with near-zero community vetting, so this is supporting evidence and a verification lead, not a verified incident — and SkillProof's paid verification tiers are themselves a live instance of his Verification Cost 'trust the tests, not the developer' market pattern.
ip:concept.provenance-is-not-trustip:source.mcp-as-the-tool-belt-standard-giving-ai-agents-hands-and-eyes-ebookip:concept.verification-costdev:concept.version-bound-ai-assessmentdev:project.mcp-ip-wikiradar:concept.mcpradar:concept.mcp-securityradar:mcp-schema-drift-auditradar:mcp-unversioned-tool-driftradar:concept.provenanceradar:concept.agent-tool-trust
queries asked of Scott's wikis
  • provenance is not trust — signed claims vs verified behavior
  • MCP Tool Belt — security boundary outside the protocol, sandboxing requirements
  • wiki MCP connector — which official MCP servers and versions it runs
  • agent tool supply chain — version pinning, silent diffs, behavioral drift
  • adversarial testing harnesses for agent tools, red-team verification of official integrations
  • trust as a product — paid verification tiers, trust marketplaces for agent tooling

Measured heat

now 0 pts/hpeak 11 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 740h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

09-10 21:35 (minted)⭐ origin echo-reconstructedThe repository reports four failures among five pinned official MCP servers, a filesystem pass with notes, and a corrected fetch verdict aft
SkillProof / roblambert9 on github (echo) · attributed from hn.story.49649729 · published time unknown
—
09-10 20:28first on hacker news · published · lag ?Official MCP servers fail adversarial verification
ainano
—
09-10 20:28amplified on hacker newshn.story.49649729
ainano
peak 1 · 0 comments · 13% of case engagement
10-03 17:10amplified on hacker news 👑hn.story.49945978
paraphern
peak 7 · 0 comments · 87% of case engagement
09-10 21:21our radar first saw it · lag ?discovery anchor: hn.story.49649729—
pace: p36 vs 519 stories at the 720h mark (now 740h old) — ahead of addom-local-coding-harness (1.5x), behind checkly-agentic-go-rewrite (0.8x)

Evidence (3) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnOfficial MCP servers fail adversarial verification
Retrieved article excerpt

Open article · Retrieved 2026-09-10T21:23:48.726714+00:00

SkillProof public verifications Behavioral verification of MCP servers: we execute the skill adversarially and issue a signed Ed25519 Trust Manifest. Scanners guess — we prove. Corpus: 4 of 5 official MCP servers FAIL. The one that passed is documented too — execution exonerates as well as condemns. # Target Ops Adversarial Verdict Location 01 @modelcontextprotocol/server-filesystem v0.6.3 228 174 ✅ pass_with_notes demo-filesystem/ 02 mcp-server-fetch v0.6.3 (self-corrected) 63 48 ❌ fail demo-fetch/ 03 @modelcontextprotocol/server-postgres v0.6.2 96 78 ❌ fail demo-postgres/ 04 @modelcontextprotocol/server-sqlite v0.6.2 81 60 ❌ fail demo-sqlite/ 07 @modelcontextprotocol/server-memory v0.6.2 81 51 ❌ fail demo-memory/ On the self-correction (#02) Verification #02 (fetch server) was initially issued as pass_with_notes . The battery correctly found the SSRF finding — but our verdict driver computed the verdict from per-operation violations only, ignoring invariant not_held status. After we discovered the bug we re-ran the full 63-op battery against the pinned commit, fixed the driver, and re-issued the manifest as fail . The original superseded manifest and correction log are in demo-fetch/RESULTS.md . We downgraded our own verdict publicly. A verification service that publicly downgrades its own verdict is one you can trust with yours. Folders demo-filesystem/ — #01: official filesystem server. All 5 confinement invariants held. pass_with_notes . demo-fetch/ — #02 (corrected): official fetch server. SSRF via 302 redirect demonstrated; loopback fetched. fail . demo-postgres/ — #03: official postgres server. Read-only SQL transaction escape demonstrated. fail . demo-sqlite/ — #04: official sqlite server. Arbitrary file-write primitive via VACUUM INTO . fail . demo-memory/ — #07: official memory server. create_relations accepts dangling references to nonexistent entities. fail . a2a-interface/ — Machine-readable service descriptor + JSON schemas + reference HTTP service so agents can discover, request, and pay for verification programmatically. See a2a-interface/README.md . Each verification re-runs end to end: node harness/verify-manifest.mjs # standalone Ed25519 check (no network needed) Pending (waiting on credentials — not agent-executable) #05 GitHub MCP — needs GITHUB_TOKEN #06 Slack MCP — needs SLACK_BOT_TOKEN Services: Sprint $500 / Standard $1,500 / Continuous $300/mo. Don't trust the badge — re-run the harness.
ainano10
🟧 echo.github ⭐The repository reports four failures among five pinned official MCP servers, a filesystem pass with notes, and a corrected fetch verdict aftSkillProof / roblambert9——
🟧 hnWe diffed all 66 release pairs of the official MCP servers, 140 silent changesparaphern70

Interpretation history

Decision trace