<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Security-Research on 7anX 的博客</title><link>https://7anX.github.io/categories/security-research/</link><description>Recent content in Security-Research on 7anX 的博客</description><generator>Hugo</generator><language>zh-cn</language><lastBuildDate>Sat, 20 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://7anX.github.io/categories/security-research/index.xml" rel="self" type="application/rss+xml"/><item><title>A2A 暴露面的安全问题</title><link>https://7anX.github.io/security-research/a2a-attack-surface/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://7anX.github.io/security-research/a2a-attack-surface/</guid><description>A2A Agent Card 设计带来的暴露面问题：什么信息不该放进卡片，为什么公开 JSON-RPC 比公开卡片更危险。</description></item><item><title>MCP 暴露面的安全问题</title><link>https://7anX.github.io/security-research/mcp-attack-surface/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://7anX.github.io/security-research/mcp-attack-surface/</guid><description>MCP 的协议设计给攻击者提供了哪些切入点，以及为什么它的暴露面和传统 HTTP API 不是一回事。</description></item></channel></rss>