<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Agentic-Tooling on Security Unlocked</title><link>https://securityunlocked.com/tags/agentic-tooling/</link><description>Recent content in Agentic-Tooling on Security Unlocked</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 19 Apr 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://securityunlocked.com/tags/agentic-tooling/index.xml" rel="self" type="application/rss+xml"/><item><title>The Protocol Is Doing Its Job</title><link>https://securityunlocked.com/weekly-intelligence/the-protocol-is-doing-its-job/</link><pubDate>Sun, 19 Apr 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/the-protocol-is-doing-its-job/</guid><description>MCP&amp;rsquo;s trust architecture makes any exposed management interface a pre-authenticated command shell by design, not by accident, and two RCE vulnerabilities in the same week reveal a deployment curve that has outrun both audit methodology and detection playbooks.</description></item><item><title>Mythos Finds Zero-Days. npm Found Three More.</title><link>https://securityunlocked.com/weekly-intelligence/mythos-finds-zero-days.-npm-found-three-more./</link><pubDate>Sun, 12 Apr 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/mythos-finds-zero-days.-npm-found-three-more./</guid><description>The same week Anthropic unveiled an AI that autonomously finds zero-days, its own CLI shipped a CVSS 9.8 command injection, exposed by a debugging artifact that had been sitting in an npm package since March 31.</description></item></channel></rss>