T3Attacking AI Systems
Attacking AI Agents & MCP
When an LLM can call tools, prompt injection stops being a text problem and becomes a code-execution one. Tool abuse, confused-deputy chains, and exploiting Model Context Protocol servers.
Intermediate2 min readassociate streamUpdated Fri Jul 31 2026 00:00:00 GMT+0000 (Coordinated Universal Time)
Learning objectives
- Explain why tool-calling turns injection into an action, not just text
- Trace a confused-deputy chain through an agent's tool permissions
- Identify the exploitable surfaces of an MCP server integration
Academy subscription
Subscribe to unlock this module
This module is part of the StrikeOps Academy subscription. Unlock every paid module, with hands-on labs and knowledge checks.
- Every paid module across all tracks
- Hands-on labs and knowledge checks
- New content as it ships
$59/ month · or $590 / year
The Reference library and Foundation starters are free to read now.