Thinking about LLM security. It's a bit like phone phreaking because it's all inband-signalling. Unlike phone phreaking I'm not sure there's a way to move to out-of-band-signalling, it's a fundamental limitation of the model.
Brought to you by https://invariantlabs.ai/blog/mcp-github-vulnerability