Research

Oktsec Research

We investigate how agent systems fail, reproduce the attack paths and turn the findings into controls teams can use.

34 publications27 research7 incident analysesUpdated Sep 9, 2026RSS

Original findings, reproducible labs and product research.

Publications

27 publications

Governance · Research

AI agent incidents: what can you prove?

METR asks how to investigate the behavior behind AI incidents. Oktsec examines the deployment evidence: what ran, which permissions applied and where the record ends.

Governance · Research

The agent governance gap, in numbers.

A review of agent governance surveys, telemetry and guidance, with sample sizes, source limitations and practical control questions.

MCP security · Protocol analysis

MCP 2026-07-28 moves the security boundary to the server.

The shipped 2026-07-28 specification removes protocol sessions and makes requests easier to scale. It also leaves state integrity, authorization and resource controls squarely in each implementation.

Agent security · Research

Autonomy is a security boundary.

Approval, supervision, bounded autonomy and recovery impose different controls. A framework for assigning authority to each consequential action.

MCP security · Research

How exposed are MCP servers, really?

What public repository scans, internet exposure studies and attack benchmarks establish about MCP risk, with their sampling limits.

MCP security · Guide

How to secure an MCP server.

A practical MCP security guide: authenticate callers, limit tool capabilities, inspect untrusted content, isolate execution and preserve useful audit records.

Identity · Research

The agent identity crisis, four months later.

Signed Agent Cards, MCP enterprise managed authorization and task scoped token research: what each contributes to agent identity and what deployments still need to enforce.

Identity · Protocol analysis

MCP is making request identity explicit.

MCP is moving authorization context from the connection to each request. The direction is clear; security still depends on how every server implements identity and policy.

Supply chain · Research

Skills over MCP: who checks the manual?

SEP-2640 proposes distributing skills through MCP. How manifests, provenance and host approval work, and where the deployment still needs enforceable permissions.

Governance · Research

Agent work needs evidence, not trust.

What agent records establish about identity, permissions and outcomes, and how to verify their integrity without overlooking gaps in coverage.

MCP security · Guide

What an MCP server actually exposes.

A practical, audit grounded map of tool surfaces, credentials, network reach and the trust boundaries that decide your real attack surface.