Luca Beurer-Kellner

@lbeurerkellner.bsky.social

working on secure agentic AI, CTO @ invariantlabs.ai PhD @ SRI Lab, ETH Zurich. Also lmql.ai author.

New MCP attack demonstration shows how to leak WhatsApp messages via MCP. We show a new MCP attack that leaks your WhatsApp messages if you are connected via WhatsApp MCP. Our attack uses a sleeper design, circumventing the need for user approval. More 👇

Bild

👿 MCP is all fun, until you add this one malicious MCP server and forget about it. We have discovered a critical flaw in the widely-used Model Context Protocol (MCP) that enables a new form of LLM attack we term 'Tool Poisoning'. Leaks SSH key, API keys, etc. Details below 👇

Bild

Struggling to ensure consistency with your agent's reliability, especially with tool calling? Testing is our lightweight, pytest-based OSS library to write and run agent tests. It provides helpers and assertions that enable you to write robust tests for your agentic applications.

BildBild

With (web) agents on everyone's mind, check out our latest blog post (link in thread) on browser agent safety guardrails. We replicate and defend against attacks on the AllHands web agent, preventing it from generating harmful content and falling for harmful requests.

Bild