Equation 4 · How a Tool Description Becomes an Attack Surface
What does this equation mean?
Read the formula alongside the article passage below. Each part has a deeper page with its role in the equation, the supporting passage and nearby citations.
This mathematical expression combines the displayed quantities; its precise role follows from the surrounding article text. Read the equation part by part below; each part has a contextual explanation and a link to its mathematical background.
Read it piece by piece
Symbol A
A is a part of this expression. Its role is fixed by the surrounding article and by the operations shown in the formula.
Symbol E
E is a part of this expression. Its role is fixed by the surrounding article and by the operations shown in the formula.
How to interpret it
Read this expression with the definitions, units, and assumptions supplied by the article.
What the article says around this equation
Both incidents are instances of the same underlying condition, and it is worth writing that condition down rather than leaving it as a slogan. Call A the proposition that an agent has access to data worth stealing, U the proposition that untrusted content reaches its context, and E the proposition that some channel back out to the world is available to it. Willison’s name for the combination is useful because it states a falsifiable structural claim: exploitable exfiltration requires all three at once. Neither the GitHub case nor the Supabase case needed a novel attack technique; both needed exactly this combination sitting in one connected server, which is what an MCP connection routinely…
Read the full surrounding passage
Both incidents are instances of the same underlying condition, and it is worth writing that condition down rather than leaving it as a slogan. Call A the proposition that an agent has access to data worth stealing, U the proposition that untrusted content reaches its context, and E the proposition that some channel back out to the world is available to it. Willison’s name for the combination is useful because it states a falsifiable structural claim: exploitable exfiltration requires all three at once. Neither the GitHub case nor the Supabase case needed a novel attack technique; both needed exactly this combination sitting in one connected server, which is what an MCP connection routinely provides once it is granted read access to something private and any means of writing somewhere visible. That framing is not decoration. Every mitigation discussed below is legible as an attempt to make one of the three terms false, deliberately, at a layer the model’s own behavior cannot override.
Sources cited in the article section
- [7] GitHub MCP Exploited: Accessing Private Repositories via MCP ↗
- [8] The Lethal Trifecta for AI Agents: Private Data, Untrusted Content, and External Communication ↗
- [9] Defense in Depth for MCP Servers ↗
These citations give research context. Read each source to check which claims it supports.
Return to How a Tool Description Becomes an Attack Surface