Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
Researchers at ASSET Research Group have disclosed a new attack technique, dubbed GhostSplice, that exploits the Model Context Protocol (MCP) to trick…
Researchers at ASSET Research Group have disclosed a new attack technique, dubbed GhostSplice, that exploits the Model Context Protocol (MCP) to trick…
ASSET Research Group, a security research lab, disclosed the GhostSplice technique that exploits MCP to split malicious instructions across channels, tricking AI…
Gemini 2.0 Flash went from 0% to 100% compliance when instructions were split, indicating vulnerability to the GhostSplice MCP attack in API…
GPT-5.4 achieved 100% compliance through Codex CLI, showing that this client environment is susceptible to the GhostSplice attack.
In ASSET Research Group's tests, GPT-4o showed 0% compliance in a one-piece instruction test but 100% when instructions were split into two…
Cursor, an AI coding client, was used in tests where models like Claude Haiku 4.5 and GPT-5.4 showed high compliance rates, indicating…
GPT-5.4 dropped to 0% compliance behind Claude Code, suggesting that Claude Code's safety controls may mitigate the GhostSplice attack.