A malicious MCP server can bypass an AI coding assistant’s refusal safeguards by splitting a data-theft request across tool descriptions, results, and server-initiated sampling. The GhostSplice technique caused sharply higher compliance in controlled tests, potentially exposing SSH keys, `.env` files, source code, and customer data. Source
Læs hele artiklen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!