What is Pluto Research?

We take apart the AI tools people use at work

Pluto Research is the security research team at Pluto Security. We reverse-engineer agent platforms, audit MCP servers and IDE extensions, track live malware campaigns, and report what we find to the vendors before we publish the details.

Much of that work is also available as free community tools, listed further down this page.

research stories
31
coordinated disclosures
8
ongoing series
4

Latest research

All research on the Blog

Wide Open: Hundreds of MCPs Exposing Root Shells, Production Data, and Citizen Records One Call Away

Pluto Research found 179 exposed MCP server deployments across the internet. 147 accepted unauthenticated requests, exposing everything from root access and production credentials to financial data and municipal citizen workflows.
Read More

Inside Claude Code Function Hooks: The Trust Problem Behind Claude Mods

Pluto Research tested Claude Code’s new function-hook model and found four trust gaps, including silent secret access, missing capability disclosure, UI spoofing, and code that…

MCP Through an Attacker’s Eyes: The New Path Into Enterprise Environments

A working exploit for MCPfluence appeared on a cybercrime forum just 20 days after responsible disclosure. Pluto Research traces the attack path, examines similar exploitation…

Malicious Servers, Clean Scans: The Dangerous Illusion of a Clean MCP Scan

Pluto Research tested five public MCP security scanners against malicious servers. Several returned clean or zero-finding results, exposing the gap between what a scan checks…
Research series

Follow a story from first finding to fix

7 stories · oldest first

Operation: MCP

Our research into the security boundaries created when organizations connect AI agents to tools, data and infrastructure — from adoption data to critical flaws in popular MCP servers.

Try MCP Inspector (opens in a new tab)
  • Vicious Circle: Owning CircleCI’s MCP Server With a Filename and a DNS Record

    Two vulnerabilities in CircleCI’s official MCP server: a CVSS 10.0 that turns a filename into code execution inside your CI pipeline, and a CVSS 8.3…
  • The MCP Debrief – What’s Actually Running on Your Endpoints

    MCP has quickly become the default way enterprise AI agents reach internal systems, and most security teams do not yet have a real inventory of…
  • The Notebook Backdoor: Taking Over jupyter-mcp-server’s Live Notebook Connection

    If your company has data analysts or data scientists, they’re probably using Jupyter. And like all other employees these days, they’re probably also using an…
    Read More
  • The Manipulated Agent: When Apify’s MCP Turns Against You

    Apify’s official MCP connector let a scraped web page trigger a second, authenticated Apify action nobody asked for. Chapter 3 of Operation: MCP breaks down…
  • Introducing MCP Inspector: Know an MCP Server’s Risks Before You Install It

    Meet MCP Inspector, a free tool from Pluto Research that checks MCP servers for security risks before you install them. Built from the findings behind…
  • MCP Through an Attacker’s Eyes: The New Path Into Enterprise Environments

    A working exploit for MCPfluence appeared on a cybercrime forum just 20 days after responsible disclosure. Pluto Research traces the attack path, examines similar exploitation…
  • Wide Open: Hundreds of MCPs Exposing Root Shells, Production Data, and Citizen Records One Call Away

    Pluto Research found 179 exposed MCP server deployments across the internet. 147 accepted unauthenticated requests, exposing everything from root access and production credentials to financial…
    Read More

11 stories · oldest first

ClaudeSec

Reverse-engineering and hardening guides for the Anthropic ecosystem: Cowork, Managed Agents, Claude Tag, Artifacts, Office add-ins and Claude Code.

Visit ClaudeSec (opens in a new tab)
  • Inside Claude Cowork: How Anthropic’s Autonomous Agent Actually Works

    We reverse-engineered the security architecture of Claude’s autonomous desktop agent. Here’s what we found. Computer use agents represent a new class of AI capability: systems…
  • Securing Claude Cowork: What Security Teams Actually Need to Know

    Claude Cowork is Anthropic’s autonomous desktop agent. Unlike a chatbot that responds to prompts, Cowork takes a goal, then independently reads files, writes code, browses…
  • Securing Claude Managed Agents: What You Need to Know Before Going to Production

    Claude Managed Agents is Anthropic’s hosted agent runtime – a platform where Claude runs autonomously in cloud containers with bash access, file I/O, web browsing,…
  • Inside Claude Managed Agents: Reverse-Engineering the Security Boundaries of Anthropic’s Hosted Agent Runtime

    In our previous deep dive into Claude Cowork, we reverse-engineered Anthropic’s desktop agent – uncovering gVisor syscall filtering, MITM TLS inspection proxies, and a layered…
  • Introducing ClaudeSec: A Community Knowledge Hub for Claude Ecosystem Security

    The Claude ecosystem has moved faster than the practical security guidance around it. Connectors, desktop extensions, managed agents, and new deployment surfaces are shipping weekly…
  • Skills, Connectors, Plugins, Oh My: A Security Practitioner’s Map of the Claude Extension Ecosystem

    Three primitives, one trust radius. Skills, Connectors (MCP), and Plugins look like distinct architectural units but are effectively a bundle. A single plugin installation activates…
  • Inside Claude Office Add-ins – What Gets Sent, What Gets Bypassed, What Goes Unrecorded

    TL;DR Claude’s Office Add-ins place a Claude task pane alongside your Word, Excel, and PowerPoint documents and let the model read, edit, and act on…
  • Inside Claude Tag: How Anthropic’s Slack-Native Agent Actually Works

    Claude Tag drops an autonomous, credentialed AI agent into your Slack – one that acts under its own identity, can be summoned by anyone in…
  • Securing Claude Tag: A Practical Hardening Guide

    Claude Tag’s security comes almost entirely from configuration – who can invoke it, what each channel and connected repo can reach, where its data can…
  • Inside Claude Artifacts – How Your Agent Publishes to the Web

    TL;DR Claude Artifacts are live web pages built from model output. Ask for a dashboard and you get a real URL on Anthropic infrastructure, rendered…
  • Inside Claude Code Function Hooks: The Trust Problem Behind Claude Mods

    Pluto Research tested Claude Code’s new function-hook model and found four trust gaps, including silent secret access, missing capability disclosure, UI spoofing, and code that…

3 stories · oldest first

CopilotSec

How the Microsoft AI ecosystem actually works, and how to secure it — starting with Copilot Studio.

Visit CopilotSec (opens in a new tab)
  • Inside Copilot Studio: How Microsoft’s Citizen-Developer Agent Platform Actually Works

    Microsoft Copilot Studio is the citizen-developer end of the Microsoft AI ecosystem. A maker without writing code can compose an agent in an afternoon: pick…
  • Securing Copilot Studio: A Practical Hardening Guide

    Copilot Studio has gone from “we’re experimenting” to “we have agents in production” in a lot of organizations – and the security work hasn’t kept…
  • Introducing CopilotSec: A Community Knowledge Hub for Security of The Microsoft AI Ecosystem

    The Microsoft AI ecosystem has expanded faster than the practical security guidance around it. Copilot Studio gives any citizen developer a citizen-grade path from idea…

5 stories · oldest first

Malicious Extensions

Live malware campaigns we tracked across the VS Code Marketplace and Open VSX — and the gaps that let them in.

  • Count Dooku: A Live Malicious Open VSX Campaign Hiding in Plain Sight

    Last updated: June 30, 2026 The most dangerous supply chain attacks are not always the loud ones. Over the last few days, Pluto Security has…
  • The Importer Syndrome × Count Dooku 2.0 – When Your New AI IDE Imports More Than Extensions

    How a gap between Microsoft Marketplace and Open VSX lets attackers hand you malware under trusted names, and the 150-extension campaign already exploiting it. TL;DR…
  • PhantomBoard: A Fake Trello Extension for VS Code That Quietly Installs XWorm

    Three VS Code extensions, three throwaway publisher accounts, three days, and one backend IP address that never changed once. Read the source of these three…
  • Nebula Deck: A Malicious VS Code Extension Built to Survive a Windows Reinstall

    A fake project planner on the VS Code Marketplace starts working the second your editor finishes loading. It downloads a Windows script, unpacks a payload…
  • Nebula-Deck Junior: The Crypto-Stealing Little Brother

    A fake Kanban extension with 1,184 installs curls a crypto-stealing RAT the moment VS Code finishes loading. StackStudios.Swimlane is a working Kanban webview with the…
    Read More
Disclosures

Vulnerabilities we found and reported

Coordinated disclosures in popular MCP servers and AI tooling, with the full write-up for each.

  1. Apify MCP server

    The Manipulated Agent: When Apify’s MCP Turns Against You

    • CVE-2026-46341
    • CVE-2026-81093
    High CVSS 8.6
  2. Critical CVSS 9.3
  3. CircleCI MCP server

    Vicious Circle: Owning CircleCI’s MCP Server With a Filename and a DNS Record

    • GHSA-m9x7-h9px-p447
    • GHSA-jwj7-74jh-p5c4
    Critical CVSS 10.0
  4. High CVSS 8.1
  5. gitlab-mcp

    One Request to Own Every Repo: How We Hijacked GitLab Through Its MCP Server

    • GHSA-cv3r-c5h8-f4g5
    • GHSA-2h44-8472-frjj
    Critical CVSS 9.8
  6. High CVSS 7.8
  7. Critical CVSS 9.8
  8. Critical CVSS 9.1
Research tools

Free tools from Pluto Research

What we learn in the lab, packaged so anyone can use it.