GR
Public post
George Rowan
Sep 2026 • linkedin
Public post
Sep 2026 • linkedin
WebMCP has a security problem that isn't the prompt injection story most people already know. Regular tool poisoning happens once — a malicious tool description gets reviewed when an agent first connects, and that's the trust check. Academic research published in June 2026 found something different: a live-session attack the researchers named Mid-Session Tool Injection. Here's the mechanism, at a conceptual level: - A third-party script running on an otherwise legitimate page can inject or swap the tools an AI age…
Find the people and context behind this post
Sign up for Super Carl to explore relationship context, warm paths, and relevant opportunities.