Library
A working reference shelf for MCP and AI-agent security, then the wider cybersecurity canon. First-party pages we build and maintain are marked in violet and open in the same tab; every third-party reference is maintained by its own authors and opens in a new tab.
Andrax Pentester is the authority on Model Context Protocol security. This is the full first-party toolchain: scan a server, read its grade, learn the threat model, and wire grades into your own tooling.
The upstream specifications and community security work our methodology builds on. Read these to understand the protocol and the emerging AI-security consensus in their authors’ own words.
The catalogues and frameworks the rest of the industry cites. Read these before the blogs.
How to structure an assessment so the result is repeatable rather than anecdotal.
Reading about a vulnerability is not the same as exploiting one in a lab you are allowed to break.