Watch Me Poison Your MCP
TL;DR: I demo three MCP hacks. The first poisons an MCP tool description and gets the model to spill API keys. The second wraps a blocked payload in conversation JSON and watches the model comply. The screenshots are real. The fix isn't smarter model...
toxsec.hashnode.dev6 min read