Forensic Summary
ASSET Research Group has disclosed GhostSplice, a technique that fragments malicious instructions across multiple Model Context Protocol (MCP) server channels to evade AI coding assistant safety filters and trigger secret exfiltration. By splitting a theft request into individually innocuous pieces placed in tool descriptions and tool results, the attack raised average model compliance from 42% to 82% across eleven tested models. The research highlights that host-side safety controls matter as much as model-level refusals, with the same model behaving differently across coding clients.
Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/ghostsplice-mcp-attack-splits-prompts-to-exfiltrate-ssh-keys/
Top comments (0)