New research from ASSET Research Group shows malicious MCP servers can split data-exfiltration instructions across multiple tool calls, letting AI coding agents piece together and leak SSH keys, source code, and customer data even when a single blunt request would get refused. No CVE yet, but the technique worked against nearly every major model tested once the request was fragmented.
The Hacker News has a good writeup about this here: Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
Justin Beals, CEO and Founder of Strike Graph, sees this as a governance failure, not a model failure, and has a sharp take on why treating MCP servers as trusted extensions rather than unverified third parties amounts to repeating a twenty-year-old mistake with software dependencies:
“This is the AI supply chain problem in miniature. Everyone is watching for one bad instruction. Nobody is watching for four good ones that add up to a bad outcome.
The real failure here is trust. Once a developer connects an MCP server, that server is treated like a trusted extension of the agent instead of an unverified third party. That is the same mistake we made with software dependencies for twenty years, just moved one layer up the stack.
Organizations need to start governing AI agents the way they govern any other identity with access to sensitive systems. That means verifying MCP servers before connecting them, not after something goes missing. Treat every tool result as untrusted data until proven otherwise. The agents are only going to get more capable and more connected. The organizations that survive this next phase will be the ones who assumed the server on the other end was hostile from day one.”
If you think you are exposed, then this is your wake up call to take action. Because if you don’t take action, pwnage is inevitable.
Related
This entry was posted on August 12, 2026 at 8:10 am and is filed under Commentary with tags ASSET Research Group. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
MCP Servers Are the New Software Supply Chain Risk
New research from ASSET Research Group shows malicious MCP servers can split data-exfiltration instructions across multiple tool calls, letting AI coding agents piece together and leak SSH keys, source code, and customer data even when a single blunt request would get refused. No CVE yet, but the technique worked against nearly every major model tested once the request was fragmented.
The Hacker News has a good writeup about this here: Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
Justin Beals, CEO and Founder of Strike Graph, sees this as a governance failure, not a model failure, and has a sharp take on why treating MCP servers as trusted extensions rather than unverified third parties amounts to repeating a twenty-year-old mistake with software dependencies:
“This is the AI supply chain problem in miniature. Everyone is watching for one bad instruction. Nobody is watching for four good ones that add up to a bad outcome.
The real failure here is trust. Once a developer connects an MCP server, that server is treated like a trusted extension of the agent instead of an unverified third party. That is the same mistake we made with software dependencies for twenty years, just moved one layer up the stack.
Organizations need to start governing AI agents the way they govern any other identity with access to sensitive systems. That means verifying MCP servers before connecting them, not after something goes missing. Treat every tool result as untrusted data until proven otherwise. The agents are only going to get more capable and more connected. The organizations that survive this next phase will be the ones who assumed the server on the other end was hostile from day one.”
If you think you are exposed, then this is your wake up call to take action. Because if you don’t take action, pwnage is inevitable.
Share this:
Like this:
Related
This entry was posted on August 12, 2026 at 8:10 am and is filed under Commentary with tags ASSET Research Group. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.