X-Ray Specs for Agents: Pentesting MCPs, Skills & the Plugin Supply Chain - Traceforce | BSides Las Vegas 2026
Abhijeet Kumar, Xia Hua & Varun Wadhwa (Traceforce) — 45 min, Common Ground, Florentine F


A tool release for inspecting what MCP servers, agent skills and plugins actually do, rather than what their descriptions claim.
Photos only — this session was not recorded, and I only caught the opening and closing slides. Notes below are limited to what those show.

The framing is the plugin supply chain as a pentest target in its own right. Every MCP server and every skill an agent loads adds capability, and that capability arrives from registries and marketplaces with very little review in between. mcp-xray is the inspection tool for that layer.
The tool and the write-up are linked from traceforce.ai.

The closing line is the argument in miniature:
Agents don’t get hacked, their tools do.
Worth reading alongside What Bounds Your Coding Agent?, which covers the same supply chain from the defensive side — roughly 15 lookalikes for every official MCP server, and configs that IT has never seen.
Frequently Asked Questions
What is mcp-xray?
An open-source tool from Traceforce for pentesting MCP servers, agent skills and the plugin supply chain — inspecting what a server actually exposes rather than trusting its description.
Why does the agent plugin supply chain need pentesting?
Because the tools are where the capability lives. An agent’s behaviour is bounded by the servers and skills it loads, and those are installed from registries and marketplaces with little review. The talk’s closing line puts it plainly: agents don’t get hacked, their tools do.