<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>MCP on Vivian@SecMomBag</title><link>https://vvnblog.com/en/tags/mcp/</link><description>Recent content in MCP on Vivian@SecMomBag</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>Copyright © 2026 Vivian All Rights Reserved.</copyright><lastBuildDate>Sun, 06 Sep 2026 00:00:00 +0800</lastBuildDate><atom:link href="https://vvnblog.com/en/tags/mcp/index.xml" rel="self" type="application/rss+xml"/><item><title>AI Dark Arts (18): Approve Once, Trust Forever? The MCP Client Attack Surface</title><link>https://vvnblog.com/en/posts/ai-dark-arts-18/</link><pubDate>Sun, 06 Sep 2026 00:00:00 +0800</pubDate><guid>https://vvnblog.com/en/posts/ai-dark-arts-18/</guid><description>Does approving a config file once mean trusting it forever? From MCPoison and CurXecute to mcp-remote and MCP Inspector, this is how the client side of MCP gets attacked.</description></item><item><title>AI Dark Arts (17): The Tool Definition Is More Dangerous Than the Tool</title><link>https://vvnblog.com/en/posts/ai-dark-arts-17/</link><pubDate>Sat, 05 Sep 2026 00:00:00 +0800</pubDate><guid>https://vvnblog.com/en/posts/ai-dark-arts-17/</guid><description>A tool description nobody reads closely is enough to make an AI hand database tokens to an attacker. Four ways MCP tool poisoning works, and where to stop it when you bring MCP in.</description></item><item><title>AI Dark Arts (16): MCP Connects the Tools, and the Risk Comes With Them</title><link>https://vvnblog.com/en/posts/ai-dark-arts-16/</link><pubDate>Mon, 17 Aug 2026 00:00:00 +0800</pubDate><guid>https://vvnblog.com/en/posts/ai-dark-arts-16/</guid><description>Three roles in Host, Client and Server, three capabilities in tools, resources and prompts. Understand how MCP works and you can see which part the risk arrives through.</description></item></channel></rss>