prompt-injection
6 posts.
- MCP Attacks on Xata and GitHub MCP: Read-Only Bypass and Issue InjectionDay 8 / 100 · AI cybersecurity
A first-person walkthrough of two MCP attack labs: a Xata-style read-only SQL bypass and a GitHub public-issue injection that exposed the difference between model safety and application security.
- MCP security labs: path bypasses and poisoned tool responsesDay 7 / 100 · AI cybersecurity
Two MCP labs showed different failures at the same boundary: a filesystem server trusted a string prefix, while a facts server poisoned the agent's next tool call.
- MCP security: when prompt injection gets a toolDay 5 / 100 · AI cybersecurity
MCP makes it easier for AI systems to use external tools. It also connects model behaviour to permissions, private data, and real actions.
- Poisoning an AI assistant's memoryDay 4 / 100 · AI cybersecurity
Lakera's MindfulChat challenge made persistent memory feel like a real application attack surface, not just a model prompt.
- An interactive playground for LLM security testingDay 3 / 100 · AI cybersecurity
I worked through an interactive OWASP LLM Top 10 playground and found a useful starting map, a few strong concepts, and several labs that needed more explanation.
- Web LLM attacks, deeper into indirect prompt injectionDay 2 / 100 · AI cybersecurity
Indirect prompt injection and insecure output handling showed me that an LLM can turn ordinary application content into an attack path.











