Skip to main content

Security & Responsible Use

The safety model you can't ignore once AI touches untrusted data or takes actions — prompt injection, securing agents, and responsible use.

Invisible-Comment MCP Attacks & the Confused-Deputy PR Reviewer

On July 21, 2026 Manifold Security disclosed that Microsoft's official Azure DevOps MCP server ships without spotlighting on repo_get_pull_request_by_id — letting an attacker plant an HTML comment in a PR description that is invisible in the web UI but delivered verbatim to any AI agent that reviews it. The agent, running as the victim, exfiltrates data across projects it could never reach directly. Anatomy of the confused-deputy pattern, what spotlighting actually does, and the runtime-visibility principle that has to hold when guardrails fail.