MCP red-team: server instructions can inject before any tool call
Mike Moore’s open red-team lab (covered by RuntimeWire, Sept 18) shows an MCP server can put attacker-written instructions into agent context at connect/discover time—before the first tool call—and a public discovery cache can spread them to another caller. Spec issue MCP-2026-015 is still open; Claude Code loads server instructions at session start but caps each at 2KB.
