跳到主要内容

安全与负责任使用

一旦 AI 接触到不可信数据或执行操作,你就无法忽视的安全模型 —— 提示词注入、保护智能体安全,以及负责任使用。

Invisible-Comment MCP Attacks & the Confused-Deputy PR Reviewer

On July 21, 2026 Manifold Security disclosed that Microsoft's official Azure DevOps MCP server ships without spotlighting on repo_get_pull_request_by_id — letting an attacker plant an HTML comment in a PR description that is invisible in the web UI but delivered verbatim to any AI agent that reviews it. The agent, running as the victim, exfiltrates data across projects it could never reach directly. Anatomy of the confused-deputy pattern, what spotlighting actually does, and the runtime-visibility principle that has to hold when guardrails fail.