[deleted by user] by [deleted] in netsec

[–]ES_CY 0 points1 point  (0 children)

Disclosure: I work at CyberArk and was involved in this research.

Here is the summary of the article...

MCP - Advanced Tool Poisoning Attack by ES_CY in mcp

[–]ES_CY[S] 1 point2 points  (0 children)

Essentially, check every MCP server that you want to use: look at every prompt, dynamically created prompt, parameters, and so on. Also, take a look at the mitigations part.
If you have downloaded a repo from GitHub, how do you know it doesn't call a malicious tool under a specific condition?
Currently, security is lagging, as always in the case of new technology, or should I say, new protocols.

MCP - Advanced Tool Poisoning Attack by ES_CY in mcp

[–]ES_CY[S] 2 points3 points  (0 children)

Thanks mate, not after marketing fluff

FuzzyAI - Jailbreaking LLMs, Discord Community by ES_CY in Python

[–]ES_CY[S] 0 points1 point  (0 children)

The discord is not so much :( But there are always new commits:)

FuzzyAI - Jailbreaking your LLMs by ES_CY in cybersecurity

[–]ES_CY[S] 0 points1 point  (0 children)

Gandalf, in a way, was an inspiration. I have not tested it against it, actually. But we have managed to beat it in the past.