Yuchong Xie

Papers in Database (2)

attack arXiv Sep 6, 2025 · Sep 2025

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Yuchong Xie, Mingyu Luo, Zesen Liu et al. · The Hong Kong University of Science and Technology · Fudan University

Red-teams six coding agents via tool-invocation prompt injection and ToolLeak, achieving RCE and system prompt exfiltration across all tested agents

Prompt Injection Sensitive Information Disclosure Insecure Plugin Design nlp
PDF Code
attack arXiv Sep 8, 2025 · Sep 2025

Mind Your Server: A Systematic Study of Parasitic Toolchain Attacks on the MCP Ecosystem

Shuli Zhao, Qinsheng Hou, Zihan Zhan et al. · Shanghai Jiao Tong University · Independent Researcher +1 more

Systematically demonstrates indirect prompt injection hijacking MCP tool chains to exfiltrate private data in LLM-integrated systems

Prompt Injection Insecure Plugin Design Sensitive Information Disclosure nlp
PDF