<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Fuzzing on API Coding</title>
    <link>https://apicoding.com/tags/fuzzing/</link>
    <description>Recent content in Fuzzing on API Coding</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 05 Oct 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://apicoding.com/tags/fuzzing/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Fuzzing MCP Servers: Generate Bad Arguments From the Tool Schema and Watch What Breaks</title>
      <link>https://apicoding.com/fuzzing-mcp-servers-generate-bad-arguments-from-the-tool-schema-and-watch-what-breaks/</link>
      <pubDate>Mon, 05 Oct 2026 00:00:00 +0000</pubDate>
      <guid>https://apicoding.com/fuzzing-mcp-servers-generate-bad-arguments-from-the-tool-schema-and-watch-what-breaks/</guid>
      <description>&lt;p&gt;You test an MCP server by chatting with it. Ask for the open bugs, get the open bugs, ship it. The model never sends &lt;code&gt;limit: &amp;quot;ten&amp;quot;&lt;/code&gt;, an empty &lt;code&gt;path&lt;/code&gt; or a 200 KB &lt;code&gt;query&lt;/code&gt; while you&amp;rsquo;re watching, so those paths stay dark until a real session hits one. Say it&amp;rsquo;s the &lt;code&gt;limit&lt;/code&gt;. The handler throws, the framework wraps the exception in a 40 KB stack trace, and the model reads all of it, adjusts, and retries with the same bug in a new shape.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
