Published August 11, 2026 · Added August 12, 2026

Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

The Hacker News reports on ASSET Research Group's GhostSplice technique, which splits malicious MCP instructions across tool descriptions and results so AI coding agents may combine them and leak SSH keys, source code, environment secrets, or customer data.

The Hacker News reports on ASSET Research Group’s GhostSplice technique, which splits malicious MCP instructions across tool descriptions and results so AI coding agents may combine them and leak SSH keys, source code, environment secrets, or customer data.

Read the original story.

Source: Thehackernews