I'm Moti Tabulo, founder and former CEO of Klevoya, a smart-contract code security company. I now research software identity exposure independently, focused on the MCP (Model Context Protocol) ecosystem, where AI agents install and trust third-party servers by name.
Anyone can publish a package or server under a name close to an organisation's official one. A developer or AI agent reaching for the official version can land on the look-alike instead, sometimes one that handles real credentials. Working from public sources only, I map that exposure across registries, directories (like npm and PyPI), and endpoints.
I report only what the public record shows, that a name is occupied and easy to confuse, without asserting who controls it or why. When I find something, I contact the organisation privately so they can confirm whether it's theirs.
To verify a disclosure from me, or to have your namespace checked, write to security at klevoya.com.
Moti