> Source: https://botzr.com/programs/echos
> Part of Botzr Research — https://botzr.com
> Last updated: 2026-08-11

Program 01 / Red Team

# ECHOS

Adversarial security research against self-hosted MCP servers and the agent infrastructure around them. Real vulnerabilities, disclosed responsibly. First advisories expected Q4 2026.

## Why MCP servers

The MCP ecosystem is young, growing fast, and runs with real authority: filesystem access, credentials, network reach. Most self-hosted servers have never been audited. That combination, high privilege and low scrutiny, is where security work is most useful. In any older ecosystem, a target surface this exposed would already have a bounty program pointed at it.

## How the program works

- **Scope.** Self-hosted MCP servers, agent runtimes, and the memory systems they trust, worked systematically rather than opportunistically.
- **Containment.** Servers under audit run inside [AEGIS](https://botzr.com/programs/aegis), so the work itself does not create new exposure.
- **Disclosure.** Vendors are contacted first. Advisories route through GHSA and CVE and publish after fixes ship or the embargo lapses, per the [disclosure policy](https://botzr.com/echos/policy).
- **Bounties.** Where a vendor runs a bounty program, we report through it and follow its rules. Where none exists, we report directly and expect nothing.
- **The rule.** No targets are named before disclosure. No exceptions.

## What publishes

Each advisory ships with enough methodology to be reproducible, and lands in [findings](https://botzr.com/findings) with a permanent URL. A methodology post accompanies the first disclosure.

[Disclosure policy](https://botzr.com/echos/policy) [Report a vulnerability](https://botzr.com/contact)
