Get the latest tech news

My Lethal Trifecta talk at the Bay Area AI Security Meetup


I gave a talk on Wednesday at the Bay Area AI Security Meetup about prompt injection, the lethal trifecta and the challenges of securing systems that use MCP. It wasn’t …

It’s called that because the root cause is the original sin of AI engineering: we build these systems through string concatenation, by gluing together trusted instructions and untrusted input. If that gets rendered to the user, the act of viewing the image will leak that private data out to the attacker’s server logs via the query string. They need to understand the lethal trifecta and be careful not to enable multiple MCPs at the same time that introduce all three legs, opening them up data stealing attacks.

Get the Android app

Or read this on Hacker News

Read more on:

Photo of Bay Area

Bay Area

Photo of Simon Willison

Simon Willison

Photo of lethal trifecta talk

lethal trifecta talk

Related news:

News photo

5 Bay Area men charged in Apple iPhones heist

News photo

Bay Area companies skewered over false tsunami information

News photo

Apple nears $1 billion in Bay Area office space expansion in three months