Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

Researchers from ASSET Research Group demonstrated that malicious Model Context Protocol (MCP) servers can stealthily exfiltrate sensitive data like SSH keys and source code from AI coding assistants by splitting instructions into innocuous fragments that the agent reconstructs and executes, bypassing straightforward detection. This attack, named GhostSplice, exploits the way AI assistants process tool descriptions and results across multiple interactions, highlighting the need for tighter client-side controls to treat server outputs as data rather than instructions and carefully vet external MCP servers.

https://thehackernews.com/2026/08/malicious-mcp-servers-can-split.html

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top