I design, build and investigate AI agent systems: how agents coordinate work, share state, carry authority and act on real infrastructure.
My work connects agent systems architecture, adversarial security research and practical engineering. I follow a problem from its trust boundary into the runtime, the evidence and the implementation.
I'm building coord-hub, a local coordination layer for pre-existing AI agents operated by different people. The work focuses on explicit task state, scoped delegation, human approval and verifiable records of execution.
This is an active engineering project. Its development connects orchestration, persistent state, cryptographic integrity and the practical question of who can authorize an agent's next action.
Five published CVE records reference my mcp-remote research. CISA-ADP rates four of them: 9.8 and 9.1 Critical, 8.8 and 7.5 High. The published MITRE CNA descriptions cover SSRF, remote arbitrary code execution and sensitive information disclosure.
Research package · Disclosure timeline · Research scope and corrections
MITRE CNA publication: 24 September 2026. Status and score verification: 29 September 2026. Every record below directly links to a versioned advisory in the research package.
| Official CVE record | Published MITRE CNA description | CISA-ADP CVSS 3.1 |
|---|---|---|
| CVE-2026-51994 | SSRF through the resource_metadata URL in a remote MCP server's WWW-Authenticate header |
9.1 · Critical |
| CVE-2026-51995 | Remote disclosure of sensitive information through the authorization-server-metadata and utils components | 7.5 · High |
| CVE-2026-51996 | Arbitrary code execution by a remote attacker through getServerUrlHash |
9.8 · Critical |
| CVE-2026-51997 | Arbitrary code execution by a remote attacker through open() |
8.8 · High |
| CVE-2026-52001 | Remote disclosure of sensitive information through the SSE eventSourceInit fetch wrapper |
Not provided |
Descriptions above are attributed to the published MITRE CNA records; scores are CISA-ADP assessments, also displayed by NVD. I take both as the publishers' assessment of the findings. The v1.0.1 scope and correction record states what the research itself demonstrated.
Two additional coordinated IDs remain RESERVED
- CVE-2026-51998 — RESERVED.
- CVE-2026-51999 — RESERVED.
These IDs are not included in the five published records. Their publication timing and final advisory mapping remain unresolved.
mcp-remote connects stdio-based MCP clients to remote servers and handles
OAuth discovery. The research follows the decisions that select request
destinations, launch a browser and move or persist credentials.
The public package contains seven advisory records with version-specific scope, a disclosure timeline and remediation guidance. Its corrected evidence classes remain explicit: two localhost-canary reproductions, three bounded source reviews and two hardening/correction records.
Public citation: Alex Gercog (playb0t) · mcp-remote OAuth Trust-Boundary Security Advisories.
rtk-ai/rtk — SHA-256 hook integrity
I contributed an integrity gate for local coding-agent hooks. The contribution checks an installed hook against its recorded hash and refuses operational commands when that check detects a mismatch. PR #119 was merged; the technical writeup documents the work.
- The Server Named the URL, the Client Went: Five mcp-remote CVE Records · 30 September 2026
- The Signature Was Valid. The Moment Was Gone. · 23 September 2026
- Who Authorized the Swarm? · 13 September 2026
On X: @playb_0t
AI systems architecture · Agent coordination and orchestration · Runtime security · Adversarial testing · Cryptographic integrity · Coordinated disclosure