← Back to article

Equation 4 · How a Tool Description Becomes an Attack Surface

What does this equation mean?

exfiltration  ⟺  A∧U∧E\text{exfiltration} \iff A \wedge U \wedge E

Read the formula alongside the article passage below. Each part has a deeper page with its role in the equation, the supporting passage and nearby citations.

This mathematical expression combines the displayed quantities; its precise role follows from the surrounding article text. Read the equation part by part below; each part has a contextual explanation and a link to its mathematical background.

Read it piece by piece

AA

Symbol A

A is a part of this expression. Its role is fixed by the surrounding article and by the operations shown in the formula.

Understand this part →

UU

Symbol U

the proposition that untrusted content reaches its context.

Understand this part →

EE

Symbol E

E is a part of this expression. Its role is fixed by the surrounding article and by the operations shown in the formula.

Understand this part →

How to interpret it

Read this expression with the definitions, units, and assumptions supplied by the article.

What the article says around this equation

Both incidents are instances of the same underlying condition, and it is worth writing that condition down rather than leaving it as a slogan. Call A the proposition that an agent has access to data worth stealing, U the proposition that untrusted content reaches its context, and E the proposition that some channel back out to the world is available to it. Willison’s name for the combination is useful because it states a falsifiable structural claim: exploitable exfiltration requires all three at once. Neither the GitHub case nor the Supabase case needed a novel attack technique; both needed exactly this combination sitting in one connected server, which is what an MCP connection routinely…
Read the full surrounding passage
Both incidents are instances of the same underlying condition, and it is worth writing that condition down rather than leaving it as a slogan. Call A the proposition that an agent has access to data worth stealing, U the proposition that untrusted content reaches its context, and E the proposition that some channel back out to the world is available to it. Willison’s name for the combination is useful because it states a falsifiable structural claim: exploitable exfiltration requires all three at once. Neither the GitHub case nor the Supabase case needed a novel attack technique; both needed exactly this combination sitting in one connected server, which is what an MCP connection routinely provides once it is granted read access to something private and any means of writing somewhere visible. That framing is not decoration. Every mitigation discussed below is legible as an attempt to make one of the three terms false, deliberately, at a layer the model’s own behavior cannot override.

Read the equation in its article →

Sources cited in the article section

These citations give research context. Read each source to check which claims it supports.

Return to How a Tool Description Becomes an Attack Surface

See this formula across 1 published context →

Browse the mathematical compendium →