Can prompt injection attack an MCP tool?
Yes. Untrusted content can influence a model to call tools incorrectly, so permissions and server-side validation must not depend on the prompt alone.
Yes. Untrusted content can influence a model to call tools incorrectly, so permissions and server-side validation must not depend on the prompt alone.