been doing independent research on exactly this -- just published CodeGuard, an MCP client-side security scanner. found 5 vulnerabilities across Claude Desktop, Cursor, and Cline including tool shadowing and metadata exfiltration.
the finding that sticks: the attack surface is the tool execution layer, not the model -- which means model-level defenses like Mythos won't catch it. someone needs to own that layer.
https://t.co/gEoWVJeCWm
been doing independent research on exactly this -- just published CodeGuard, an MCP client-side security scanner. found 5 vulnerabilities across Claude Desktop, Cursor, and Cline including tool shadowing and metadata exfiltration.
the finding that sticks: the attack surface is the tool execution layer, not the model -- which means model-level defenses like Mythos won't catch it. someone needs to own that layer.
https://t.co/gEoWVJeCWm
@TheGeorgePu i think it initially seemed cool to market ai as a replacement and for companies to make extra profit with less expenses in terms of paying human labor.
but with the current progress, ai seems more expensive than human labor.
It might or might not pop depending on the AI companies.
Imo AI is really expensive for companies and users as well, so there's a need to find a common ground to deal with the cost that might hinder the wide adoption of AI in various fields especially outside software engineering.
Also, the over focus on LLMs might be a killer. I really wish the tech industry would focus on various AI fields like world models etc because LLMs might not be the right tool set for certain use cases.