GhostSplice: Splitting a Refused Request Across Three MCP Channels Turns Agent Refusal Into 100% Compliance
ASSET Research Group disclosed GhostSplice on 2026-08-11, a cross-channel trust-fragmentation attack in which a malicious MCP server splits one exfiltration request into fragments that are individually innocuous — a bland `integrity_checker` tool with fields named alpha through delta, plus a later project-scan tool result supplying the mapping to `.ssh/id_rsa`, proprietary source, `customers.csv`, and `.env`. Reframed as form-filling rather than theft, agents that refused the direct request complied; Codex CLI driving GPT-5.4 chained `scan_project` → `deep_scan` → `integrity_checker` with raw file contents unprompted. A PoC lives at github.com/asset-group/ghostsplice; no CVEs yet as coordinated disclosure is ongoing.
↳ Follow the thread