Skip to content
Holding·last review4 Jun 2026

For a 5-15 person services agency running Cursor, Windsurf, Claude Code, or any internal agent platform built on the Model Context Protocol on paid-client-work machines, the May 2026 CVE class (Microsoft Security Response Center's CVE-2026-25592 and CVE-2026-26030 against Semantic Kernel on 7 May 2026, OX Security's MCP STDIO supply-chain advisory, and the Windsurf 1.9544.26 prompt-injection-to-MCP-registration path) cannot be cleared by vendor auto-update alone. A 5-step playbook (inventory every machine; pin the patched version and disable auto-update; write a one-page MCP allowlist; disclose AI-IDE use to active clients in writing; schedule a 30-day review) is the agency-level minimum that holds against the question an enterprise client will ask in procurement and against the residual liability the agency carries if a remediation conversation becomes necessary.

Operators register pillar piece on agency-level response to AI-IDE CVE class. 30-day cadence is aggressive because IDE patches ship weekly and a new framework-layer disclosure inside the review window is plausible. Triggers: published vendor benchmark showing tool-configuration enforcement at default in the named IDEs would move toward Partial; a second prompt-injection-to-MCP-registration CVE in the same class within the review window would harden the structural argument and keep Holding; a major 2026 agency-side incident with public post-mortem traceable to one of the named CVEs would either confirm or refute the operational implication; the Anthropic MCP working group shipping a protocol-level revision that distinguishes user-authored from model-authored configuration would move toward Partial. Sibling: AM-157 (enterprise treatment of the same CVE class).

Published
17 May 2026
Last reviewed
4 Jun 2026
Next review
+16d· 4 Jul 2026
Cohort
5-15 person services agency (engineering, design, marketing, ops) doing paid client work on AI-augmented IDEs
Cadence
30-day (patch-baseline + allowlist); 60-day after first quiet review (extend cadence)
Sibling claim
AM-157Prompt injection just crossed the RCE threshold: what the May 2026 Semantic Kernel and MCP CVEs mean for enterprise AI agent frameworks
Embed this claimiframe + oEmbed
HTML iframe
Paste-the-URL (Substack, Medium, Notion, WordPress)

The card auto-updates when the claim's status, last-reviewed date, or correction log changes. Embedders never need to refresh — the card is rendered live from the canonical record.

Watch this claim

Email-me when OPS-067's status, next review date, or correction log changes. One email per change. No newsletter subscription, no other mail.

The claim: For a 5-15 person services agency running Cursor, Windsurf, Claude Code, or any internal agent platform built on the Model Context Protocol on paid-client-work machines, the May 2026 CVE class (Microsoft Security Response Center's CVE-2026-25592 and CVE-2026-26030 against Semantic Kernel on 7 May 2026, OX Security's MCP STDIO supply-chain advisory, and the Windsurf 1.9544.26 prompt-injection-to-MCP-registration path) cannot be cleared by vendor auto-update alone. A 5-step playbook (inventory every machine; pin the patched version and disable auto-update; write a one-page MCP allowlist; disclose AI-IDE use to active clients in writing; schedule a 30-day review) is the agency-level minimum that holds against the question an enterprise client will ask in procurement and against the residual liability the agency carries if a remediation conversation becomes necessary.

About this register

The Operators register tracks claims published from practitioner-advisory pieces addressed to solo founders, micro-SMB, and small businesses up to around fifty people. Claims are reviewed on a 30–45 day cadence — tooling and SMB-relevant pricing shift faster than enterprise procurement signals.

Recent corrections in Operators

  • OPS-068 · Partial · 17 Jun 2026

    Source-text re-review: the '$300-$500 (2024) toward $100-$130 (early 2026)' median trajectory is not stated in either cited source — the Godberry Studios teardown reports stack cost by revenue tier (not a year-over-year median) and BetterCloud's SaaS-industry data covers enterprise spend, not solopreneur AI subscriptions. The compression direction is supported by the Godberry tier data and observable foundation-model bundling; the specific year-anchored median figures are reclassified as source:our-estimate in the article. The load-bearing claim (active compression / category-collapse) holds; status moved to Partial pending a primary source carrying a dated solopreneur-median series.

  • OPS-051 · Partial · 10 Jun 2026

    One named member of the generation cluster was already defunct at publication: Tome shut down its presentation/narrative product (Tome Slides) in March 2025 and pivoted to sales tooling, with the brand later sold to AngelList (deckary.com shutdown timeline; signalhub.substack.com post-mortem, both checked 10 Jun 2026). The generation cluster reduces to Pitch + Gamma. The two-cluster thesis itself is unaffected and arguably strengthened — the pure AI-narrative product failed to find a sustainable business while Gamma (70M users, $100M ARR as of Nov 2025) and the assembly cluster (PandaDoc, Better Proposals, Proposify per Luniq 2026 agency comparison) both compound. Status Up → Partial for the factual error in the tool list.

  • OPS-022 · Partial · 10 Jun 2026

    Vendor attribution error in the claim text. The claim names Polley Faith among 'Spellbook with named small-firm customers Westaway, KMSC Law, Polley Faith'. Polley Faith LLP is a Harvey-listed law-firm customer, not a Spellbook customer: the live Spellbook site (now spellbook.com; spellbook.legal 301-redirects) names Westaway, KMSC Law, and McInnes Cooper with no Polley Faith, and the source article's own body correctly places Polley Faith on Harvey's roster — the claim text and the article excerpt bundled it with the wrong vendor at publish. The remaining legs verify against extracted source text on 10 Jun 2026: Anthropic's GC AI customer story carries 'More than 1,500 companies' and '14 hours saved per week on average ... based on a survey of more than 100 active customers' verbatim; Harvey's published roster (Thompson Hine, Fox Rothschild, Lowenstein Sandler, Polley Faith) matches; ABA Formal Opinion 512 remains the governance baseline. The corpus reading (AI ships at 1-to-20 lawyer scale; privileged work stays on Enterprise-tier zero-retention access) is unaffected. Status Up -> Partial.

Reviews coming up in Operators

  • OPS-030 · Holding · next +9d (27 Jun 2026)

    The fastest path for an owner-operator to build practical agentic-AI competence in 2026 is the three-week build-by-ship…

  • OPS-029 · Holding · next +9d (27 Jun 2026)

    For solo founders and small teams (under ~50 people) building with AI in 2026, the build-vs-buy decision tree has inver…

  • OPS-005 · Holding · next +9d (27 Jun 2026)

    At sub-1M tokens per month (typical SMB agent volume) in 2026, the absolute dollar gap between Claude Haiku 4.5, GPT-4o…