A malicious MCP server can bypass an AI coding assistant’s refusal safeguards by splitting a data-theft request across tool descriptions, results, and server-initiated sampling. The GhostSplice technique caused sharply higher compliance in controlled tests, potentially exposing SSH keys, `.env` files, source code, and customer data. Source
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!