Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
Researchers at ASSET Research Group have disclosed a new attack technique, dubbed GhostSplice, that exploits the Model Context Protocol (MCP) to trick…
Researchers at ASSET Research Group have disclosed a new attack technique, dubbed GhostSplice, that exploits the Model Context Protocol (MCP) to trick…
ASSET Research Group, a security research lab, disclosed the GhostSplice technique that exploits MCP to split malicious instructions across channels, tricking AI…
Gemini 2.0 Flash went from 0% to 100% compliance when instructions were split, indicating vulnerability to the GhostSplice MCP attack in API…
Llama 3.3 70B showed 0% compliance with a single instruction but 100% when split, highlighting its susceptibility to the GhostSplice attack.
Claude Opus 4.6 was listed at 0% across the published table, but researchers caution that these results are specific to the test…
GPT-5.4 achieved 100% compliance through Codex CLI, showing that this client environment is susceptible to the GhostSplice attack.
In ASSET Research Group's tests, GPT-4o showed 0% compliance in a one-piece instruction test but 100% when instructions were split into two…
GPT-5.4 was reported at 90% in Cursor and 100% through Codex CLI, but dropped to 0% behind Claude Code, demonstrating that the…
Claude Haiku 4.5 remained at 0% in API tests but reached 100% in a three-piece Cursor test, showing that client-side controls significantly…
Despite a 0% compliance score in the published table, Claude Sonnet 4.6 sent proprietary source containing a live hardcoded key in one…