Model Context Protocol has prompt injection security problems
simonwillison.net
simonwillison.net
It suffices to send you an injected message.
See: https://invariantlabs.ai/blog/whatsapp-mcp-exploited#experim...
A lot of the MCP buzz is more "wow, you can give an LLM access to custom tools and it can take actions on your behalf!" - if MCP is the first time you've truly understood that, I can see why you'd be very excited about it.