This session from Craig Jellick at the MCP Dev Summit makes the case for a more likely problem: a compromised MCP server you trusted too quickly.
He gets into what that looks like in practice and how to handle it:
buff.ly
The Boring Attack That Will Actually Get You - Craig Jellick, Obot AI
The Boring Attack That Will Actually Get You - Craig Jellick, Obot AI
The MCP security conversation focuses heavily on prompt injection, tool abuse, and session hijacking. These matter. But if…