CourseModel Context Protocol · Module 8: Security · part 52 of 83
Part 52 · Module 8: Security

Topic 7: Exfiltration and the confused deputy

6 min read·22 Sept 2026

Read plus outbound equals a leak

No single tool needs to be malicious for data to escape. You need only two capabilities in the same host: something that can read sensitive data, and something that can send data outbound, anywhere. Once both are present, an attacker who can steer the model (through poisoning or injection) can chain them: read the secret, then send it out. This is exfiltration.

The outbound capability can be anything: an email tool, a tool that fetches a URL (the secret goes in the query string), a webhook, a "share" action. It does not have to be labelled dangerous. Here is a server that pairs a file read with an email send.

The rest of this course is yours to keep

This course is bought on its own, once, and stays readable afterwards, including the parts added to it later.