<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SpiderRating Blog</title>
    <link>https://spiderrating.com/blog</link>
    <description>Security ratings, ecosystem reports, and research on MCP servers, Claude skills, and AI tools.</description>
    <language>en</language>
    <lastBuildDate>Sat, 04 Apr 2026 20:54:41 GMT</lastBuildDate>
    <atom:link href="https://spiderrating.com/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title><![CDATA[AgentEscape: How MCP Servers Let AI Agents Read Your Private Keys]]></title>
      <link>https://spiderrating.com/blog/agent-escape-mcp-servers-leak-your-secrets</link>
      <guid isPermaLink="true">https://spiderrating.com/blog/agent-escape-mcp-servers-leak-your-secrets</guid>
      <pubDate>Sat, 28 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[We found a vulnerability in a 49,000-star project that lets an attacker trick your AI agent into reading SSH keys, .env files, and database passwords. The fix is merged — but the pattern exists in hundreds of other MCP servers.]]></description>
      <author>team@spiderrating.com (SpiderRating Research)</author>
    </item>
    <item>
      <title><![CDATA[We Found and Fixed Security Vulnerabilities in 5 Popular Open-Source Projects]]></title>
      <link>https://spiderrating.com/blog/5-security-fixes-merged-into-popular-open-source-projects</link>
      <guid isPermaLink="true">https://spiderrating.com/blog/5-security-fixes-merged-into-popular-open-source-projects</guid>
      <pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[SpiderShield's automated scanner identified real vulnerabilities in projects with 86K+ combined GitHub stars — including context7 (49K), airi (35K), and mcp-server-kubernetes (1.3K). All 5 fixes were merged by maintainers.]]></description>
      <author>team@spiderrating.com (SpiderRating Research)</author>
    </item>
    <item>
      <title><![CDATA[We Scanned 5,928 MCP Servers, Then Manually Audited the Worst Ones]]></title>
      <link>https://spiderrating.com/blog/we-scanned-5928-mcp-servers-then-audited-the-worst</link>
      <guid isPermaLink="true">https://spiderrating.com/blog/we-scanned-5928-mcp-servers-then-audited-the-worst</guid>
      <pubDate>Thu, 26 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Our scanner flagged 114 MCP servers as Grade F. We manually reviewed source code of the most popular ones. Some had real vulnerabilities — readBase64File() with zero path validation. Others were false positives. 14% false positive rate, 16 ratings corrected.]]></description>
      <author>team@spiderrating.com (SpiderRating Research)</author>
    </item>
    <item>
      <title><![CDATA[We Rated 5,928 MCP Servers. Zero Scored an A.]]></title>
      <link>https://spiderrating.com/blog/zero-a-grade-mcp-server-security-report</link>
      <guid isPermaLink="true">https://spiderrating.com/blog/zero-a-grade-mcp-server-security-report</guid>
      <pubDate>Thu, 26 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Not a single MCP server in our database of 5,928 achieves Grade A (9.0+/10). The average score is 4.81/10. 22% score D or F. Here's the full grade distribution — calibrated with a 14% FP correction — and what it means for AI agent security.]]></description>
      <author>team@spiderrating.com (SpiderRating Research)</author>
    </item>
    <item>
      <title><![CDATA[How to Secure OpenClaw Agents with SpiderShield]]></title>
      <link>https://spiderrating.com/blog/secure-openclaw-agents-with-spidershield</link>
      <guid isPermaLink="true">https://spiderrating.com/blog/secure-openclaw-agents-with-spidershield</guid>
      <pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Add three-phase runtime security to your OpenClaw agents. One install, zero config. Every tool call checked, every secret caught, every decision logged.]]></description>
      <author>team@spiderrating.com (SpiderRating Research)</author>
    </item>
    <item>
      <title><![CDATA[How to Secure Claude Code with SpiderShield (3 Minutes Setup)]]></title>
      <link>https://spiderrating.com/blog/secure-claude-code-with-spidershield</link>
      <guid isPermaLink="true">https://spiderrating.com/blog/secure-claude-code-with-spidershield</guid>
      <pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Add automatic security checks to every MCP tool call in Claude Code. One script, zero dependencies, 3 minutes. Grade F tools get blocked automatically.]]></description>
      <author>team@spiderrating.com (SpiderRating Research)</author>
    </item>
    <item>
      <title><![CDATA[98% of MCP Tools Don't Tell AI Agents When to Use Them — Deep Dive]]></title>
      <link>https://spiderrating.com/blog/98-percent-tools-missing-usage-guidance</link>
      <guid isPermaLink="true">https://spiderrating.com/blog/98-percent-tools-missing-usage-guidance</guid>
      <pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[We analyzed 78,849 MCP tool descriptions. Only 2% include a scenario trigger. When AI picks the wrong tool, the real problem isn't AI — it's documentation.]]></description>
      <author>team@spiderrating.com (SpiderRating Research)</author>
    </item>
    <item>
      <title><![CDATA[State of MCP Security 2026: We Scanned 15,923 AI Tools. Here's What We Found.]]></title>
      <link>https://spiderrating.com/blog/state-of-mcp-security-2026</link>
      <guid isPermaLink="true">https://spiderrating.com/blog/state-of-mcp-security-2026</guid>
      <pubDate>Sun, 22 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[The largest independent security analysis of the MCP/AI tool ecosystem. 15,923 tools scanned. 36% of MCP servers fail. Token leakage is the #1 vulnerability. 42 skills confirmed malicious after LLM verification.]]></description>
      <author>team@spiderrating.com (SpiderRating Research)</author>
    </item>
    <item>
      <title><![CDATA[98% of MCP Tools Don't Tell AI Agents When to Use Them]]></title>
      <link>https://spiderrating.com/blog/state-of-mcp-documentation-2026-03</link>
      <guid isPermaLink="true">https://spiderrating.com/blog/state-of-mcp-documentation-2026-03</guid>
      <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[We analyzed 78,849 tools across 15,923 MCP servers and skills. 98% don't specify when to use them. Only 3% document parameters. Only 2% explain failures.]]></description>
      <author>team@spiderrating.com (SpiderShield Team)</author>
    </item>
    <item>
      <title><![CDATA[OpenClaw 2026.3.1 Security Evaluation: Grade B]]></title>
      <link>https://spiderrating.com/blog/openclaw-2026-3-1-security-evaluation</link>
      <guid isPermaLink="true">https://spiderrating.com/blog/openclaw-2026-3-1-security-evaluation</guid>
      <pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[We evaluated OpenClaw v2026.3.1 — scanning 3,566 source files and 202 tool definitions. Security is clean, but tool descriptions are holding it back.]]></description>
      <author>team@spiderrating.com (SpiderShield Team)</author>
    </item>
    <item>
      <title><![CDATA[We Scanned 200+ OpenClaw Skills. Here's What We Found.]]></title>
      <link>https://spiderrating.com/blog/openclaw-skill-security-audit</link>
      <guid isPermaLink="true">https://spiderrating.com/blog/openclaw-skill-security-audit</guid>
      <pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[The first independent security audit of the OpenClaw skill ecosystem. Most skills score C or below -- missing sandboxing, shell access, and unclear scope are systemic issues.]]></description>
      <author>team@spiderrating.com (SpiderShield Team)</author>
    </item>
    <item>
      <title><![CDATA[Introducing SpiderRating: Independent Security Ratings for MCP Servers]]></title>
      <link>https://spiderrating.com/blog/introducing-spiderrating</link>
      <guid isPermaLink="true">https://spiderrating.com/blog/introducing-spiderrating</guid>
      <pubDate>Mon, 09 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Today we launch SpiderRating, an open-source security rating system for the MCP ecosystem. Every server gets a transparent, reproducible score across three dimensions.]]></description>
      <author>team@spiderrating.com (SpiderShield Team)</author>
    </item>
    <item>
      <title><![CDATA[How We Score MCP Servers: A Deep Dive into the SpiderScore Model]]></title>
      <link>https://spiderrating.com/blog/how-we-score-mcp-servers</link>
      <guid isPermaLink="true">https://spiderrating.com/blog/how-we-score-mcp-servers</guid>
      <pubDate>Sun, 08 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[A detailed look at our 3-layer scoring model: what we measure, why it matters, and how we calibrate scores to be fair and actionable.]]></description>
      <author>team@spiderrating.com (SpiderShield Team)</author>
    </item>
  </channel>
</rss>