MCP Prompt Injection Before the First Tool Call

Chronological Source Flow
Back

AI Fusion Summary

Indirect prompt injection occurs when attackers embed hidden instructions within data, such as support tickets, to manipulate LLM agents into performing unauthorized actions like issuing refunds. Additionally, research into MCP reveals vulnerabilities before the first tool call, specifically within the instructions field of initialize and server/discover. A critical finding indicates that shared caches can distribute poisoned instructions to multiple callers, transforming a client-side issue into a broader gateway problem for system security.
Community Comments
Loading updates...
0