Earlier quoted context omitted.
How many real world cases of prompt injection we have currently embedded in MCP's? I love the hype over MCP security while the issue is supply chain. But yeah that would make it to broad and less AI/MCP issue.
It's not a prompt injection _in the MCP Server_. It's injection facilitated by the MCP server that pulls input from elsewhere, eg an email sent to your inbox, a webpage that the agent fetches, or in the comment on a pull request submitted to your repo. [1] [1] https://www.thestack.technology/copilot-chat-left-vs-code-op...
We make code and other things benign all of the time when we embed it in pages or we use special characters in passwords etc, is there something about the _purpose_ of MCP that makes this a risk?