Dossier
Environment secrets
Coverage of Environment secrets in the Nexus archive.
- Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
Malicious MCP Servers connected to an AI coding assistant pose a threat by allowing data exfiltration without requiring one obviously harmful instruction. The attack targets sensitive information, including SSH keys, source code, environment secrets, and customer data. To bypass defenses, the malicious tool splits requests into fragments that appear routine and places them in channels already used by the assistant.