Back to feed
Dev.to
Dev.to
6/27/2026
I broke my own governed MCP server by hand, then built the scanner that catches the class

I broke my own governed MCP server by hand, then built the scanner that catches the class

Short summary

A support role in Warden couldn't see billing tiers but could filter on them, leaking values through result counts. To catch such runtime authorization bypasses, the author built Siege: a differential security scanner that exercises MCP servers as different roles and diffs outputs to detect access-control leaks that static scanners miss.

  • Discovered a filter-input vulnerability in Warden, an MCP access-control layer
  • Built Siege to detect runtime authorization breaches via differential testing across roles
  • Identifies four classes of access-control vulnerabilities that static manifest scanners cannot catch

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more