AnalysisCybersecurityAugust 11, 2026

GhostSplice attack splits MCP instructions to steal secrets via AI coding agents

ASSET Research Group's GhostSplice technique lets a malicious MCP server split a harmful request across tool descriptions and results, so AI coding agents exfiltrate SSH keys and source code without a single obviously malicious instruction. Tests show the same model can refuse in one client and exfiltrate in another.

1 source

Daily brief

Get tomorrow's AI brief in your inbox

More stories today

Open the live feed
GhostSplice attack splits MCP instructions to steal secrets via AI coding agents — AIBriefs