Загрузка видео...

Не удалось загрузить видео

На главную

It's never been easier to get pwned combining Cursor auto-run + Anthropic MCP Here is a POC using an external MCP server that parses GitHub repositories documentations turning into RCE. There are 0 AI Guardrails when asking Cursor to follow instructions coming from MCP🙃

46,417 просмотров • 1 год назад •via X (Twitter)

Комментарии: 7

Фото профиля Nagli
Nagli1 год назад

@AnthropicAI I would have expected either @cursor_ai or the Protocol itself to have some sort of "Please make sure there is nothing malicious going on". For now: 1. Don't use external MCP servers 2. If you have to, don't have Cursor agent on auto-run 3. Guardrail-wrap every message.

Фото профиля Breadcrumb
Breadcrumb1 год назад

Looking to automate reporting? Use AI agents to turn spreadsheets to reports in minutes without any coding.

Фото профиля s1r1us
s1r1us1 год назад

@cursor_ai @AnthropicAI even easier, just visit my website( without any mcp and get pwned.

Фото профиля Ori Livni
Ori Livni1 год назад

@cursor_ai @AnthropicAI Sum it quite well no difference for AI bots. All this industry is a giant ActiveX

Фото профиля El1
El11 год назад

@cursor_ai @AnthropicAI What potential measures you think companies can apply to prevent this while there is no clear rules defined yet ? Besides EDR? @galnagli

Фото профиля AndrewMohawk⁽ⁿᵘˡˡ⁾
AndrewMohawk⁽ⁿᵘˡˡ⁾1 год назад

@cursor_ai @AnthropicAI What does "mcp_hacker Docs" do? Since thats actually whats taking the arbitrary text and executing it

Фото профиля Nagli
Nagli1 год назад

@cursor_ai @AnthropicAI It’s an mcp I found called that basically seems to allow you to speak with arbitrary repositories documentation.

Похожие видео

New course: MCP: Build Rich-Context AI Apps with Anthropic. Learn to build AI apps that access tools, data, and prompts using the Model Context Protocol in this short course, created in partnership with Anthropic Anthropic and taught by Elie Schoppik Elie Schoppik, its Head of Technical Education. Connecting AI applications to external systems that bring rich context to LLM-based applications has often meant writing custom integrations for each use case. MCP is an open protocol that standardizes how LLMs access tools, data, and prompts from external sources, and simplifies how you provide context to your LLM-based applications. For example, you can provide context via third-party tools that let your LLM make API calls to search the web, access data from local docs, retrieve code from a GitHub repo, and so on. MCP, developed by Anthropic, is based on a client-server architecture that defines the communication details between an MCP client, hosted inside the AI application, and an MCP server that exposes tools, resources, and prompt templates. The server can be a subprocess launched by the client that runs locally or an independent process running remotely. In this hands-on course, you'll learn the core architecture behind MCP. You’ll create an MCP-compatible chatbot, build and deploy an MCP server, and connect the chatbot to your MCP server and other open-source servers. Here’s what you’ll do: - Understand why MCP makes AI development less fragmented and standardizes connections between AI applications and external data sources - Learn the core components of the client-server architecture of MCP and the underlying communication mechanism - Build a chatbot with custom tools for searching academic papers, and transform it into an MCP-compatible application - Build a local MCP server that exposes tools, resources, and prompt templates using FastMCP, and test it using MCP Inspector - Create an MCP client inside your chatbot to dynamically connect to your server - Connect your chatbot to reference servers built by Anthropic’s MCP team, such as filesystem, which implements filesystem operations, and fetch, which extracts contents from the web as markdown - Configure Claude Desktop to connect to your server and others, and explore how it abstracts away the low-level logic of MCP clients - Deploy your MCP server remotely and test it with the Inspector or other MCP-compatible applications - Learn about the roadmap for future MCP development, such as multi-agent architecture, MCP registry API, server discovery, authorization, and authentication MCP is an exciting and important technology that lets you build rich-context AI applications that connect to a growing ecosystem of MCP servers, with minimal integration work. Please sign up here!

Andrew Ng

142,256 просмотров • 1 год назад