/me - pretends to be shocked
Reposted from
Simon Willison
Model Context Protocol has prompt injection security problems
https://simonwillison.net/2025/Apr/9/mcp-prompt-injection/
https://simonwillison.net/2025/Apr/9/mcp-prompt-injection/
Comments
By design no way to distinguish data / instructions, trusted / untrusted sources.