logoalt Hacker News

ANSI escape injection in MCP servers: Hidden from humans, visible to AI

25 pointsby xgpyc2qplast Tuesday at 7:01 AM9 commentsview on HN

Comments

illliilllltoday at 9:27 AM

Every year is apparently a good year for developers to figure out how terminals have worked for decades?

Just… don’t trust inputs you don’t fully control, there’s nothing else to it.

show 2 replies
qwertoxtoday at 9:18 AM

> DAST is the natural way to catch this class of flaw. The Bright scanner...

hahahaatoday at 9:31 AM

So cat -v is no longer harmful?

Daffrintoday at 10:21 AM

[dead]

Avery29today at 10:02 AM

[dead]

xgpyc2qplast Tuesday at 7:01 AM

[dead]

doodlebytetoday at 8:54 AM

This is a really interesting class of failure. It feels like we're going to see more cases where the "human view" and the "LLM view" of the same data diverge. Have you run into similar issues outside of MCP as well, or is this mostly specific to terminal-based tool interactions?

show 2 replies