Otto Support – An MCP, Agentic-AI Security Challenge
Bishop Fox released otto-support, a public CTF and vulnerable MCP (Model Context Protocol) server designed to teach AI agent security through hands-on exploitation. The challenge simulates real-world attack surfaces where AI assistants interact with tools, internal services, and local resources, requiring participants to escalate privileges, exfiltrate data, and execute code. The research contextualizes emerging MCP vulnerabilities including MCP Inspector's unauthenticated RCE (CVE-2025-49596) and OpenClaw's plaintext credential storage and prompt injection flaws.