2026-10-11 17:11 UTC

Follow-up testing will show that ANSI escape-sequence injection can manipulate AI-visible tool output while evading human review across multiple real MCP servers, prompting server or client-side mitigations.

state: expiredheat: lowuncertainty: highconvergesscott: mediummcp-server-security agent-tool-injection prompt-injectionBright Security

What is this?

The supplied evidence titles attribute to Bright Security research describing ANSI escape-sequence injection in MCP server output: malicious content can allegedly be hidden from human viewers while remaining visible to an AI consuming the underlying tool output. The supplied web results are unrelated dictionary and social-media pages, so they do not independently establish the technique, testing across multiple real MCP servers, or any resulting client- or server-side mitigations. Those elements remain a follow-up hypothesis rather than a demonstrated event in the provided material.

Why it matters to Scott

The alleged human/model visibility split concretely converges with Scott’s taint-tracking and chat-era trust-model claims, and could require output sanitization or canonical logging changes in his MCP IP Wiki and `ask` terminal agent. It is not yet high-confidence because the supplied material does not establish cross-server reproduction or actual mitigations; validation would turn it from a relevant attack pattern into actionable engineering evidence.
ip:concept.taint-trackingip:concept.chat-era-trust-modeldev:project.mcp-ip-wikidev:project.askradar:concept.prompt-injectionradar:concept.agent-securityradar:concept.agent-harnesses
queries asked of Scott's wikis
  • MCP tool-output trust boundaries
  • agent tool-result prompt injection
  • human-visible versus model-visible output
  • terminal control characters in agent harnesses
  • sanitizing untrusted MCP responses
  • tool-output review and provenance

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnANSI escape injection in MCP servers: Hidden from humans, visible to AIxgpyc2qp6036
🟧 echo.blog ⭐The research describes detecting ANSI escape-sequence injection in MCP servers, where malicious content can be hidden from human viewers whiBright Security——

Interpretation history

Decision trace