<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
    <channel>
        <title>Llm-Security - Tag - arleo.eu</title>
        <link>https://www.arleo.eu/en/tags/llm-security/</link>
        <description>Llm-Security - Tag - arleo.eu</description>
        <generator>Hugo -- gohugo.io</generator><language>en</language><lastBuildDate>Fri, 21 Aug 2026 22:12:46 &#43;0000</lastBuildDate><atom:link href="https://www.arleo.eu/en/tags/llm-security/" rel="self" type="application/rss+xml" /><item>
    <title>Indirect Prompt Injection on MCP: Our Real Defenses</title>
    <link>https://www.arleo.eu/en/posts/mcp-indirect-prompt-injection-defenses/</link>
    <pubDate>Fri, 21 Aug 2026 22:12:46 &#43;0000</pubDate>
    <author>Jmr</author>
    <guid>https://www.arleo.eu/en/posts/mcp-indirect-prompt-injection-defenses/</guid>
    <description><![CDATA[<div class="featured-image">
                <img src="/images/posts/mcp-indirect-prompt-injection-defenses-featured.jpg" referrerpolicy="no-referrer">
            </div><h2 id="in-short">In short</h2>
<p><strong>Scope:</strong> defenses actually implemented in arleo.eu&rsquo;s MCP server (<code>mcp-hugo-server-go</code>) against indirect prompt injection and tool poisoning, available since v1.9.3: systematic provenance tagging (<code>content_provenance</code>), a tool-registry fingerprint (<code>tool_registry_digest</code>), explicit untrusted-derivation self-declaration, a delete-confirmation gate, a documented threat model.
<strong>Not covered:</strong> this isn&rsquo;t an incident — this article documents a defense architecture, not an after-the-fact fix. What remains out of scope (client-side mitigation, semantic filtering deliberately rejected) is detailed further below.</p>]]></description>
</item>
</channel>
</rss>
