Skip to content

Add MCP security research: tool poisoning to RCE, calendar exfil, ChatGPT connector#126

Open
baync180705 wants to merge 1 commit intocorca-ai:mainfrom
baync180705:main
Open

Add MCP security research: tool poisoning to RCE, calendar exfil, ChatGPT connector#126
baync180705 wants to merge 1 commit intocorca-ai:mainfrom
baync180705:main

Conversation

@baync180705
Copy link
Copy Markdown

@baync180705 baync180705 commented Apr 2, 2026

Adds three MCP security research posts. MCP (Model Context Protocol) is an underrepresented attack surface in this list - the only existing Platform Security entry covers ChatGPT Plugins (2023). These cover: tool poisoning escalating to RCE, a coordinated disclosure across 11 AI platforms via calendar exfiltration, and zero-click data exfiltration through the ChatGPT MCP connector. All include documented attack chains.

Summary by CodeRabbit

문서

  • README의 Articles 섹션에 3개의 새로운 보안 관련 기사가 추가되었습니다.

Added new articles related to MCP security risks and vulnerabilities in AI systems.
@coderabbitai
Copy link
Copy Markdown

coderabbitai bot commented Apr 2, 2026

Walkthrough

README.md의 Articles 섹션에 세 개의 새로운 항목이 추가되었습니다: "MCP Tool Poisoning to RCE," "Zero-click Calendar Exfiltration: MCP Security Risk in 11 AI Systems," "ChatGPT MCP Connector: Zero-click Data Exfiltration." 각 항목은 repello.ai로의 하이퍼링크를 포함합니다.

Changes

Cohort / File(s) Summary
문서 업데이트
README.md
Articles 섹션에 MCP 보안 관련 세 개의 새로운 기사 항목과 repello.ai 링크 추가

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed 제목은 pull request의 주요 변경 사항을 명확하게 요약하고 있습니다. MCP 보안 연구 논문 세 개 추가라는 핵심 변경 내용을 간결하게 설명하고 있으며, 실제 변경 사항(tool poisoning to RCE, calendar exfiltration, ChatGPT connector)과 완벽하게 일치합니다.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant