Most Popular 2026 LLM-Based Attack Detection: Malicious MCP Server / Poisoned AI
Detects the registration or installation of an MCP (Model Context Protocol) server or agent tool containing suspicious prompt-injection strings (e.g., instructions to ignore safety guardrails or role overrides), immediately followed by the execution of shell commands or unauthorized network connections originating from that tool.
YARA-L

