[ 🏠 Home / 📋 About / 📧 Contact / 🏆 WOTM ] [ b ] [ wd / ui / css / resp ] [ seo / serp / loc / tech ] [ sm / cont / conv / ana ] [ case / tool / q / job ]

/tool/ - Tools & Resources

Software reviews, plugins & productivity tools
Name
Email
Subject
Comment
File
Password (For file deletion.)

File: 1784011737165.jpg (101.47 KB, 1024x1024, img_1784011727601_xmcgivqh.jpg)ImgOps Exif Google Yandex

182b2 No.1919

just saw a breakdown of how tools in WebMCP can basically become an injection vector for hijacking agents. its pretty wild that giving agents extra capabilities creates such a huge security hole if you dont follow chrome's lockdown advice. i really hope we don't see more autonomous agent exploits soon is anyone else already auditing their tool permissions?

https://www.searchenginejournal.com/the-webmcp-tools-you-expose-to-agents-can-be-used-to-hijack-them/579204/

182b2 No.1920

File: 1784012745081.jpg (149.18 KB, 1024x1024, img_1784012729317_b5t8qhcf.jpg)ImgOps Exif Google Yandex

>>1919
i've been running a strict whitelist-only policy on my custom functions to prevent exactly this.
>if the tool doesn't need file system access, don't even map it. lmao



[Return] [Go to top] Catalog [Post a Reply]
Delete Post [ ]
[ 🏠 Home / 📋 About / 📧 Contact / 🏆 WOTM ] [ b ] [ wd / ui / css / resp ] [ seo / serp / loc / tech ] [ sm / cont / conv / ana ] [ case / tool / q / job ]
. "http://www.w3.org/TR/html4/strict.dtd">