Tool-Call Injection in LLM Agents: Why Your MCP Server Is the New Attack Surface An LLM agent that can read email, browse the web and run shell commands is useful precisely because it acts on untrusted input. That combination is also why the Model Context Protocol (MCP) server sitting behind the...

Source: [Dev.to](https://dev.to/stark_zhuang_df5076f35c68/tool-call-injection-in-llm-agents-why-your-mcp-server-is-the-new-attack-surface-p37)

Sponsored