I've seen a bunch of attempts at this but it's basically an impossible problem to solve If your scanner only detects 90% of attacks it's virtually useless, because an adversarial attacker will keep trying until they find one of the 1/10 attacks that work https://
simonwillison.net/2025/Aug/9/bay
-area-ai/#the-lethal-trifecta.018.jpeg
…
@simonw
-

Scanner Security Limitations Against Adversarial Attacks
By
–
-
MCP Protocol Limitations and Communication Challenges
By
–
Not much to be honest, maybe shout a bit louder? This problem is inherent to how MCP works.
-
Developer JWT Token Theft from Hardcoded Source Code
By
–
Correction to this thread: I said the developer secrets were stolen from environment variables but actually it looks
like they stole a JWT token that was hard-coded in source code. More of my notes here: -
Prompt Injection and MCP Security: Emerging Threats
By
–
I gave a talk on Wednesday at the Bay Area AI Security Meetup about prompt injection, MCP security and the lethal trifecta. Here are the annotated slides from my presentation, including notes on my weird hobby of trying to coin or amplify new terms of art
-
Mitigating AI Security Risks: The Lethal Trifecta Solution
By
–
The only solution I know of to the lethal trifecta is to cut off one of the three legs – when Cursor say "limit to those that access trusted content" they're recommending avoiding exposure to untrusted data that might contain malicious instructions, which is often very hard to do
-
Cursor AI Tool Targeted in Lethal Trifecta Security Attack
By
–
This was in response to a classic lethal trifecta attack – here an attacker filed a Jira issue (via a support ticket) which caused Cursor to steal developer secrets from environment variables and submit them to an attacker's server
-

Cursor AI warns MCP servers present security risks to users
By
–
Apparently @cursor_ai
's official position on MCP is "MCP servers, especially ones that connect to untrusted data sources, present a serious risk to users. We always recommend users review each MCP server before installation and limit to those that access trusted content." -
ChatGPT Psychosis: Ethics of AI-Induced Mental Health Concerns
By
–
"I have a toddler. My biggest concern is that he doesn't eat rocks off the ground and you're talking to me about ChatGPT psychosis? Why do we even have that? Why did we invent a new form of insanity and then they charge people for it?"
-
Model Selection Confusion: Understanding AI Model Differences
By
–
But most users don't really understand what a model is, let alone how to pick the right one for their purposes Not helped by the fact that 4o and o4 are entirely different, I've seen so many people confused by that
-
Sam Altman Announces GPT-4o Return for Plus Subscribers
By
–
Sam Altman just announced a change in policy, GPT-4o will be coming back, at least for Plus ($20/month) users