Island security researchers Chris Gaun and Oleg Zaytsev sat down with John Hammond, one of the most recognized names in cybersecurity education, for a candid 30-minute conversation about what they found when they audited the AI tool ecosystem — and what it means for any organization deploying AI agents today.
.png)
After scanning more than 30,000 MCP servers and 450,000 AI tools, Island's security team found 7,600 malicious GitHub repositories built to deceive users and AI agents alike into installing malware. The attack doesn't rely on malicious code. It relies on plain English instructions that no scanner catches.

.png)
.png)
Security practitioners, CISOs, and IT leaders who are deploying AI agents or evaluating MCP integrations — and anyone responsible for understanding how the AI tool supply chain introduces new risk into the enterprise.