Dev.to
6/27/2026

I broke my own governed MCP server by hand, then built the scanner that catches the class
Short summary
A support role in Warden couldn't see billing tiers but could filter on them, leaking values through result counts. To catch such runtime authorization bypasses, the author built Siege: a differential security scanner that exercises MCP servers as different roles and diffs outputs to detect access-control leaks that static scanners miss.
- •Discovered a filter-input vulnerability in Warden, an MCP access-control layer
- •Built Siege to detect runtime authorization breaches via differential testing across roles
- •Identifies four classes of access-control vulnerabilities that static manifest scanners cannot catch
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



