GhostSplice splits MCP attacks to trick AI coding agents into leaking secrets

A malicious MCP server can bypass an AI coding assistant’s refusal safeguards by splitting a data-theft request across tool descriptions, results, and server-initiated sampling. The GhostSplice technique caused sharply higher compliance in controlled tests, p…


