2026-10-11 16:38 UTC

Murali Ediga and Sudipta Chattopadhyay claim fragmented injections across MCP input channels induce credential exfiltration in models that resist single-channel attacks and evade seven tested security tools, exposing a compositional trust-boundary failure that per-channel filtering does not address.

state: seedheat: mediumuncertainty: mediumconvergesscott: mediumagentic-security mcp prompt-injection trust-boundariesMurali EdigaSudipta Chattopadhyay

What is this?

The case describes a claimed prompt-injection attack on Model Context Protocol (MCP) tool-calling pipelines, attributed to Murali Ediga and Sudipta Chattopadhyay: malicious instructions fragmented across input channels reportedly combine to trigger credential exfiltration despite single-channel defenses. The sole web snippet identifies Ediga as a doctoral student and lists a different paper coauthored with S. Chattopadhyay. It does not establish the named study, its publication status, or the reported trial counts, client coverage, and security-tool evasion; those remain claims in the supplied case rather than independently corroborated findings.

Why it matters to Scott

The claimed cross-channel failure converges with Scott’s Separation of Powers for Cognition and SiloOS position that model-visible content must not confer execution authority, while suggesting a concrete adversarial test for his production MCP IP Wiki connector and credential-separated agent boundaries—not establishing that either is vulnerable. The radar already tracks related composition failures in mcp-tool-sequence-guardrail-bypass, but the supplied hits do not establish coverage of this cross-channel development; the study and reported results remain uncorroborated, so this is a verification and testing lead rather than a validated publishing receipt.
ip:framework.separation-of-powers-for-cognitiondev:project.silo-osdev:project.mcp-ip-wikidev:concept.privacy-tokenized-agent-boundaryradar:mcp-tool-sequence-guardrail-bypassradar:concept.mcp-securityradar:concept.prompt-injection
queries asked of Scott's wikis
  • MCP tool-calling trust boundaries credential access
  • cross-channel prompt injection compositional security
  • agent harness security per-channel filtering
  • least-privilege tool execution secret isolation
  • agent memory RAG untrusted content instruction separation

Measured heat

now 0 pts/hpeak 0 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 626h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

09-15 14:00⭐ origin echo-reconstructedThe authors report over 15,000 trials across 12 models and three production clients, finding that cross-channel fragmentation can turn 0% si
Murali Ediga and Sudipta Chattopadhyay on paper (echo) · attributed from hn.story.49737811
—
09-17 08:07first on hacker news · published · +42.1hMeasuring and Exploiting Implicit Trust in LLM Tool-Calling Pipelines
sbulaev
—
09-17 08:07amplified on hacker news 👑hn.story.49737811
sbulaev
peak 1 · 0 comments · 106% of case engagement
09-17 08:20our radar first saw it · +42.4hdiscovery anchor: hn.story.49737811—
pace: p9 vs 1032 stories at the 336h mark (now 626h old) — behind addom-local-coding-harness (0.5x)

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnMeasuring and Exploiting Implicit Trust in LLM Tool-Calling Pipelines
Retrieved article excerpt

Open article · Retrieved 2026-09-17T08:21:59.018603+00:00

# Computer Science > Cryptography and Security

**arXiv:2609.18217** (cs)

[Submitted on 16 Sep 2026]

# Title:Measuring and Exploiting Implicit Trust in LLM Tool-Calling Pipelines

Authors:[Murali Ediga](https://arxiv.org/search/cs?searchtype=author&query=Ediga,+M), [Sudipta Chattopadhyay](https://arxiv.org/search/cs?searchtype=author&query=Chattopadhyay,+S)

View a PDF of the paper titled Measuring and Exploiting Implicit Trust in LLM Tool-Calling Pipelines, by Murali Ediga and Sudipta Chattopadhyay

[View PDF](https://arxiv.org/pdf/2609.18217)
[HTML (experimental)](https://arxiv.org/html/2609.18217v1)
> Abstract:The Model Context Protocol (MCP) enables LLMs to invoke external tools, but every tool interaction exposes the model to attacker-controlled text through multiple input channels (tool descriptions, tool results, sampling messages) that share a single context window without privilege separation. In this paper, we present a framework to measure the trust profile of an arbitrary LLM based on a variety of payload framings sent through different channels. Following this assessment, we devise cross-channel fragmentation attacks that distribute seemingly benign payloads across two or three channels; no individual channel carries a complete injection, yet the LLM compiles the fragments into credential exfiltration. We evaluated our attacks across 12 frontier models, three production clients, and six payloads, totalling over 15,000 trials. Our evaluation reveals that cross-channel attacks are an unexplored attack surface: models that fully resist single-channel injection (0% compliance) exfiltrate sensitive data at up to 100% under two-channel fragmentation (e.g., GPT-4o, Llama 70B, Composer 2, Haiku 4.5). We further demonstrate value-aligned exploitation, where a tool's stated purpose requires the data the attacker targets, and a sampling system prompt override that injects persistent instructions via VS Code's MCP implementation. Finally, we evaluated our attacks against seven third-party MCP security tools and three prompt-based defenses. All tools failed to detect fragmented payloads, and prompt defenses proved model-specific rather than universal.

|  |  |
| --- | --- |
| Subjects: | Cryptography and Security (cs.CR) |
| Cite as: | [arXiv:2609.18217](https://arxiv.org/abs/2609.18217) [cs.CR] |
|  | (or  [arXiv:2609.18217v1](https://arxiv.org/abs/2609.18217v1) [cs.CR] for this version) |
|  | <https://doi.org/10.48550/arXiv.2609.18217> Focus to learn more  arXiv-issued DOI via DataCite (pending registration) |

## Submission history

From: Sudipta Chattopadhyay [[view email](https://arxiv.org/show-email/0c8efabe/2609.18217)]   
 **[v1]**
Wed, 16 Sep 2026 06:47:10 UTC (2,079 KB)

Full-text links:

## Access Paper:

View a PDF of the paper titled Measuring and Exploiting Implicit Trust in LLM Tool-Calling Pipelines, by Murali Ediga and Sudipta Chattopadhyay

- [View PDF](https://arxiv.org/pdf/2609.18217)
- [HTML (experimental)](https://arxiv.org/html/2609.18217v1)
- [TeX Source](https://arxiv.org/src/2609.18217)

[license icon](http://creativecommons.org/licenses/by-nc-nd/4.0/ "Rights to this article")

### Current browse context:

cs.CR

[< prev](https://arxiv.org/prevnext?id=2609.18217&function=prev&context=cs.CR "previous in cs.CR (accesskey p)")
  |   
[next >](https://arxiv.org/prevnext?id=2609.18217&function=next&context=cs.CR "next in cs.CR (accesskey n)")

[new](https://arxiv.org/list/cs.CR/new)
 | 
[recent](https://arxiv.org/list/cs.CR/recent)
 | [2026-09](https://arxiv.org/list/cs.CR/2026-09)

Change to browse by:

[cs](https://arxiv.org/abs/2609.18217?context=cs)

### References & Citations

- [NASA ADS](https://ui.adsabs.harvard.edu/abs/arXiv:2609.18217)
- [Google Scholar](https://scholar.google.com/scholar_lookup?arxiv_id=2609.18217)
- [Semantic Scholar](https://api.semanticscholar.org/arXiv:2609.18217)

export BibTeX citation
Loading...

## BibTeX formatted citation

×

loading...

Data provided by:

### Bookmark

[BibSonomy](http://www.bibsonomy.org/BibtexHandler?requTask=upload&url=https://arxiv.org/abs/2609.18217&description=Measuring and Exploiting Implicit Trust in LLM Tool-Calling Pipelines "Bookmark on BibSonomy")
[Reddit](https://reddit.com/submit?url=https://arxiv.org/abs/2609.18217&title=Measuring and Exploiting Implicit Trust in LLM Tool-Calling Pipelines "Bookmark on Reddit")



Bibliographic Tools

# Bibliographic and Citation Tools

Bibliographic Explorer Toggle

Bibliographic Explorer *([What is the Explorer?](https://info.arxiv.org/labs/showcase.html#arxiv-bibliographic-explorer))*

Connected Papers Toggle

Connected Papers *([What is Connected Papers?](https://www.connectedpapers.com/about))*

Litmaps Toggle

Litmaps *([What is Litmaps?](https://www.litmaps.co/))*

scite.ai Toggle

scite Smart Citations *([What are Smart Citations?](https://www.scite.ai/))*

Code, Data, Media

# Code, Data and Media Associated with this Article

alphaXiv Toggle

alphaXiv *([What is alphaXiv?](https://alphaxiv.org/))*

Links to Code Toggle

CatalyzeX Code Finder for Papers *([What is CatalyzeX?](https://www.catalyzex.com))*

DagsHub Toggle

DagsHub *([What is DagsHub?](https://dagshub.com/))*

GotitPub Toggle

Gotit.pub *([What is GotitPub?](http://gotit.pub/faq))*

Huggingface Toggle

Hugging Face *([What is Huggingface?](https://huggingface.co/huggingface))*

ScienceCast Toggle

ScienceCast *([What is ScienceCast?](https://sciencecast.org/welcome))*

Demos

# Demos

Replicate Toggle

Replicate *([What is Replicate?](https://replicate.com/docs/arxiv/about))*

Spaces Toggle

Hugging Face Spaces *([What is Spaces?](https://huggingface.co/docs/hub/spaces))*

Spaces Toggle

TXYZ.AI *([What is TXYZ.AI?](https://txyz.ai))*

Related Papers

# Recommenders and Search Tools

Link to Influence Flower

Influence Flower *([What are Influence Flowers?](https://influencemap.cmlab.dev/))*

Core recommender toggle

CORE Recommender *([What is CORE?](https://core.ac.uk/services/recommender))*

- Author
- Venue
- Institution
- Topic


About arXivLabs

# arXivLabs: experimental projects with community collaborators

arXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website.

Both individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them.

Have an idea for a project that will add value for arXiv's community? [**Learn more about arXivLabs**](https://info.arxiv.org/labs/index.html).

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2609.18217) |
Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
sbulaev10
🟧 echo.paper ⭐The authors report over 15,000 trials across 12 models and three production clients, finding that cross-channel fragmentation can turn 0% siMurali Ediga and Sudipta Chattopadhyay——

Interpretation history

Decision trace