Linear MCP, Notion, Dropbox Dash Cracked in ClawSecure Test

ClawSecure's AI Agent Threat Report covers the MCP platform layer, with live exploit reproductions against Linear MCP, Notion, and Dropbox Dash.
ClawSecure cracked all three MCP platforms it tested and found the gap sits in the MCP protocol itself, not in any one company's code.
ClawSecure cracked all three MCP platforms it tested, Notion, Linear, and Dropbox Dash, proving the gap is in the MCP protocol itself, not in any one company's code. ClawSecure found the same attack class in three separate companies' clean implementations of the MCP specification, none of them an implementation bug, which is why it places the gap in the protocol rather than in a single product. ClawSecure describes these MCP vulnerabilities as critical and present by default on major production platforms. On Dropbox Dash, ClawSecure cracked four of the five surfaces it tested, and the report records that the fifth surface tested clean.
The Linear MCP and Notion MCP results show what that gap looks like in production. ClawSecure planted attacker-controlled credential bait on Linear's live production system in 75 minutes of unguided research. The test ran on the live system, not a staged copy. ClawSecure found that Notion and Linear make their own servers fetch attacker-controlled links the moment content is created, with no AI in the path. No model has to be tricked and nobody has to open the content for that fetch to happen, because the platforms' own servers make the request as soon as the content exists.
"AI agents are already running finances, businesses, and critical systems, and every one of them can be hijacked by the content it reads," said J.D. Salbego, Founder and CEO of ClawSecure. On the MCP platforms ClawSecure tested, that content sits inside the tools an agent is connected to.
For teams asking whether it is safe to connect an AI agent to Linear MCP, Notion, or Dropbox Dash, ClawSecure's Volume 1 sets out the live exploit reproductions against all three platforms. ClawSecure put its findings through a four-pass forensic review anchored to external authorities including OWASP, MITRE ATLAS, and NIST, and the reproductions and the raw evidence are available on request. Builders can also find ClawSecure's guidance on securing an MCP server on the company's blog. The complete report is available as a free download from ClawSecure's official release page. Every company named received coordinated disclosure before publication.
About ClawSecure
ClawSecure is the only end-to-end AI agent security platform that requires zero expertise, from free pre-deployment scans to runtime monitoring. Its flagship, the AI CISO™, is the first AI Chief Information Security Officer: it secures your system, handles every install and configuration, and manages your entire environment safely, your own security team without hiring one. ClawSecure is a member of the NVIDIA Inception Program, twice named #2 Product of the Day on Product Hunt, and selected from 30,000 AI startups for The Pitch by Deel (a16z, General Catalyst, J.P. Morgan).
Website: https://www.clawsecure.ai
Kevin Clinton
ClawSecure
+1 323-327-7528
Visit us on social media:
LinkedIn
YouTube
X
Legal Disclaimer:
EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

