▲ | Graphon1 5 days ago | ||||||||||||||||
It's not a prompt injection _in the MCP Server_. It's injection facilitated by the MCP server that pulls input from elsewhere, eg an email sent to your inbox, a webpage that the agent fetches, or in the comment on a pull request submitted to your repo. [1] [1] https://www.thestack.technology/copilot-chat-left-vs-code-op... | |||||||||||||||||
▲ | alias_neo 4 days ago | parent [-] | ||||||||||||||||
I'm completely new to this, and know nothing about MCP, but why is it that when it fetches that stuff it isn't just "content"? We make code and other things benign all of the time when we embed it in pages or we use special characters in passwords etc, is there something about the _purpose_ of MCP that makes this a risk? | |||||||||||||||||
|