<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cliff Smith on The Trail of Bits Blog</title><link>https://miscreants.github.io/blog.trailofbits.com/authors/cliff-smith/</link><description>Recent content in Cliff Smith on The Trail of Bits Blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 28 Jul 2025 00:00:00 -0400</lastBuildDate><atom:link href="https://miscreants.github.io/blog.trailofbits.com/authors/cliff-smith/index.xml" rel="self" type="application/rss+xml"/><item><title>We built the security layer MCP always needed</title><link>https://miscreants.github.io/blog.trailofbits.com/2025/07/28/we-built-the-security-layer-mcp-always-needed/</link><pubDate>Mon, 28 Jul 2025 07:00:00 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2025/07/28/we-built-the-security-layer-mcp-always-needed/</guid><description>Today we’re announcing the beta release of mcp-context-protector, a security wrapper for LLM apps using the Model Context Protocol (MCP). It defends against the line jumping attacks documented earlier in this blog series, such as prompt injection via tool descriptions and ANSI terminal escape codes.</description></item><item><title>Securing the software supply chain with the SLSA framework</title><link>https://miscreants.github.io/blog.trailofbits.com/2024/10/01/securing-the-software-supply-chain-with-the-slsa-framework/</link><pubDate>Tue, 01 Oct 2024 09:00:58 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2024/10/01/securing-the-software-supply-chain-with-the-slsa-framework/</guid><description>Software supply chain security has been a hot topic since the Solarwinds breach back in 2020. Thanks to the Supply-chain Levels for Software Artifacts (SLSA) framework, the software industry is now at the threshold of sustainably solving many of the biggest challenges in securely building and distributing open-source software. SLSA is a […]</description></item><item><title>Internet freedom with the Open Technology Fund</title><link>https://miscreants.github.io/blog.trailofbits.com/2024/01/15/internet-freedom-with-the-open-technology-fund/</link><pubDate>Mon, 15 Jan 2024 08:30:54 -0500</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2024/01/15/internet-freedom-with-the-open-technology-fund/</guid><description>Trail of Bits cares about internet freedom, and one of our most valued partners in pursuit of that goal is the Open Technology Fund (OTF). Our core values involve focusing on high-impact work, including work with a positive social impact. The OTF’s Red Team Lab […]</description></item></channel></rss>