Tal Zamir September 22, 2025 Exposed AI Agents in the Wild: How a Public MCP Server Let Us Peek Inside Its Host