Skip to content
View playb0t's full-sized avatar

Block or report playb0t

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
playb0t/README.md

Alex Gercog (playb0t), AI systems engineering and security research: selected work referenced by 5 published CVE records, with CISA-ADP scores of 9.8 and 9.1 Critical, 8.8 and 7.5 High

Alex Gercog · AI systems engineer & security researcher

I design, build and investigate AI agent systems: how agents coordinate work, share state, carry authority and act on real infrastructure.

My work connects agent systems architecture, adversarial security research and practical engineering. I follow a problem from its trust boundary into the runtime, the evidence and the implementation.

Building agent coordination infrastructure

I'm building coord-hub, a local coordination layer for pre-existing AI agents operated by different people. The work focuses on explicit task state, scoped delegation, human approval and verifiable records of execution.

This is an active engineering project. Its development connects orchestration, persistent state, cryptographic integrity and the practical question of who can authorize an agent's next action.

Featured research · Official CVE publications

Five published CVE records reference my mcp-remote research. CISA-ADP rates four of them: 9.8 and 9.1 Critical, 8.8 and 7.5 High. The published MITRE CNA descriptions cover SSRF, remote arbitrary code execution and sensitive information disclosure.

Research package · Disclosure timeline · Research scope and corrections

Published CVE records

MITRE CNA publication: 24 September 2026. Status and score verification: 29 September 2026. Every record below directly links to a versioned advisory in the research package.

Official CVE record Published MITRE CNA description CISA-ADP CVSS 3.1
CVE-2026-51994 SSRF through the resource_metadata URL in a remote MCP server's WWW-Authenticate header 9.1 · Critical
CVE-2026-51995 Remote disclosure of sensitive information through the authorization-server-metadata and utils components 7.5 · High
CVE-2026-51996 Arbitrary code execution by a remote attacker through getServerUrlHash 9.8 · Critical
CVE-2026-51997 Arbitrary code execution by a remote attacker through open() 8.8 · High
CVE-2026-52001 Remote disclosure of sensitive information through the SSE eventSourceInit fetch wrapper Not provided

Descriptions above are attributed to the published MITRE CNA records; scores are CISA-ADP assessments, also displayed by NVD. I take both as the publishers' assessment of the findings. The v1.0.1 scope and correction record states what the research itself demonstrated.

Two additional coordinated IDs remain RESERVED

These IDs are not included in the five published records. Their publication timing and final advisory mapping remain unresolved.

The research

mcp-remote connects stdio-based MCP clients to remote servers and handles OAuth discovery. The research follows the decisions that select request destinations, launch a browser and move or persist credentials.

The public package contains seven advisory records with version-specific scope, a disclosure timeline and remediation guidance. Its corrected evidence classes remain explicit: two localhost-canary reproductions, three bounded source reviews and two hardening/correction records.

Public citation: Alex Gercog (playb0t) · mcp-remote OAuth Trust-Boundary Security Advisories.

Engineering contribution

rtk-ai/rtk — SHA-256 hook integrity

I contributed an integrity gate for local coding-agent hooks. The contribution checks an installed hook against its recorded hash and refuses operational commands when that check detects a mismatch. PR #119 was merged; the technical writeup documents the work.

Writing

On X: @playb_0t

Focus

AI systems architecture · Agent coordination and orchestration · Runtime security · Adversarial testing · Cryptographic integrity · Coordinated disclosure

Pinned Loading

  1. rtk-hook-integrity rtk-hook-integrity Public

    SHA-256 hook-integrity verification I shipped to rtk-ai/rtk (PR #119) — hardening the agent auto-approve hook against hijacking.

  2. mcp-remote-oauth-security mcp-remote-oauth-security Public

    Seven evidence-bounded OAuth trust-boundary security advisories for geelen/mcp-remote, reviewed through 0.1.38.

    2 1