The AI ecosystem is the wild west 🐎 You connect a new MCP, skill, or agent... and find out it's sketchy after the damage is done.
We built Market Space - discover & install AI tools that are secure by default 🪐
plutonium.pluto.security
The security assumption every AI team gets wrong: "As long as trust_remote_code=False is set, we are safe." ❌
We put that to the test. What we uncovered is a critical RCE vulnerability in @huggingface Transformers (CVE-2026-4372) that completely bypasses this control.
A thread
Last time, we published ClaudeSec - our security-first hub for the Claude ecosystem.
Now, CopilotSec is officially LIVE.
A new community knowledge hub for security of the Microsoft AI ecosystem, powered by Pluto.
Ever wanted a single place to understand what Microsoft AI
ClaudeSec is officially LIVE!
Meet the new security-first hub for the Claude ecosystem, powered by @pluto_security.
❓Always yearned for a unified search of all existing extensions?
❓Ever wondered what ones are flagged as high-risk?
❓Dreaming of knowing how to deploy safely