We called the MCP flaw a design decision, not a bug. Then a leading security firm confirmed it.
The industry treated a Model Context Protocol weakness as an implementation mistake to be patched. We argued it was baked into the protocol's design. When OX Security reached the same conclusion, the timestamps settled who saw it first.
Everyone was treating it as a bug to patch.
A weakness surfaced in how MCP handles trust between agents and the servers they call. The reflex was predictable: log it, patch it, move on. A bug has an owner and a fix. That framing felt safe — and it was wrong.
A bug is an accident. This was a choice — and choices don't get patched away.
The record shows the order things happened.
We publish the reframe
Publicly, on the record: the MCP weakness is a design decision, not a defect. Contain it at your boundary now.
Independent confirmation
A leading application-security firm reaches the same conclusion — validating the call after the fact.
The firms that wait for confirmation are already a step behind the ones who published it. Read the risk early, or inherit it late.
Get the read before the market catches up.
Three ways in, matched to how early you want the signal.
The reframe brief
Why the MCP flaw is structural — and how to contain it at your boundary today.
Get the brief →Emerging-threat briefing
A working session on the protocol risks likely to be confirmed next — before they are.
Book a briefing →Strategic intel retainer
Ongoing early reads on protocol and agent risk, scoped to your stack and roadmap.
Start the retainer →