build1 publisher
Red-team lab lands attacker prose in an MCP agent's context before any tool runs
Mike Moore's harness shows MCP's server-authored instructions field placing hostile prose in an agent's context, and a caching proxy passing it to a second caller. The harness measures where the text lands, with no model in the loop.
Publishers:runtimewire.com
Reality
- Evidence68
- Adoption58
- Hype gap+8
- Incentives45
- Confidence66