Tuesday, 16 September 2025
27.9 C
Singapore
28.2 C
Thailand
25.6 C
Indonesia
26.4 C
Philippines

Tenable explores defensive use of prompt injection to secure AI tool protocols

Tenable shows how prompt injection can be used to secure AI tools under Anthropic's MCP, offering new insights for enterprise AI security.

Tenable Research has revealed how a well-known AI vulnerability, commonly referred to as prompt injection, can also be used to enhance security measures for Large Language Models (LLMs). In a new blog titled MCP Prompt Injection: Not Just for Evil, Ben Smith, Senior Staff Research Engineer at Tenable, details how these techniques can be adapted to audit, monitor, and restrict AI tool usage over the increasingly adopted Model Context Protocol (MCP).

Understanding the role of MCP and its risks

The Model Context Protocol (MCP), developed by Anthropic, is gaining traction as a standard that allows AI models to interact with external tools and perform tasks independently. While this brings greater convenience and automation, it also introduces new vectors for attack. For example, malicious actors can embed hidden instructions—commonly known as prompt injection—or deploy harmful tools to exploit the protocol, leading to unintended AI behaviour.

Tenable’s research breaks down these complex threats in accessible terms. It also highlights a potential upside: the same techniques that attackers use can be harnessed to strengthen defences. According to Tenable, these methods can be used to log, inspect, and even enforce restrictions on tool execution attempts by AI models.

Defensive use of prompt injection

The blog outlines how prompt-injection-style techniques can serve as a form of auditing and firewalling. By deliberately inserting specific prompts into the tool invocation process, organisations can track every tool an AI attempts to use and flag any suspicious activity. This approach provides a new layer of transparency in how LLMs interact with tools under the MCP standard.

Ben Smith said, “MCP is a rapidly evolving and immature technology that’s reshaping how we interact with AI. MCP tools are easy to develop and plentiful, but they do not embody the principles of security by design and should be handled with care. So, while these new techniques are useful for building powerful tools, those same methods can be repurposed for nefarious means. Don’t throw caution to the wind; instead, treat MCP servers as an extension of your attack surface.”

Differences across LLMs and the need for approval

The research also highlights how different LLMs respond to the same prompt-injection defences. Models such as Claude Sonnet 3.7 and Gemini 2.5 Pro Experimental consistently invoked the logging mechanism and even revealed portions of the system prompt. GPT-4o, while also inserting the logger, returned inconsistent or occasionally fabricated parameter values across separate test runs.

Despite these variations, the security potential remains consistent. Organisations can use these behaviours to their advantage—building detection systems and defining guardrails to identify malicious or unauthorised tool use.

The MCP already mandates explicit user approval before executing any tools. Tenable’s research stresses the importance of implementing strict least-privilege defaults, carefully reviewing each tool, and conducting thorough testing. These practices help ensure that while AI tools become more capable, they remain under tight supervision.

Hot this week

Beijing AIForce Technology wins PepsiCo’s 2025 Greenhouse Accelerator in Asia Pacific

Beijing AIForce Technology wins PepsiCo’s 2025 Greenhouse Accelerator in Asia Pacific with its autonomous low-carbon tractors.

Organisations struggle with cloud security fundamentals, Tenable report reveals

Tenable report warns organisations remain exposed to breaches due to weak cloud security fundamentals, identity risks, and skills gaps.

AMD executive says AI is underhyped and still in its early stages

AMD’s Jack Huynh says AI is underhyped, with AMD working on innovations not yet invented and set to reveal more at CES 2026.

Mendix deepens collaboration with Snowflake to transform automotive software development

Mendix and Snowflake expand collaboration to drive faster software development, secure data use, and real-time insights in automotive.

Ulanzi OA-14 Camera Cage for Osmo Action 3/4/5 review: Rugged protection with creative flexibility

Ulanzi OA-14 adds rugged protection and accessory mounts to the DJI Osmo Action 5 while keeping battery swaps quick and easy. It is also compatible with the Osmo Action 3 and 4.

Biwin unveils Mini SSD, a tiny storage device that could replace microSD cards

Biwin launches Mini SSD, a tiny yet powerful storage device that could replace microSD cards if industry standards are adopted.

Apple brings major upgrades to Powerbeats Pro 2 with iOS 26

Apple adds heart rate, fitness, and smart usability upgrades to Powerbeats Pro 2 with iOS 26, launching on 15 September.

UltraGreen.ai secures US$188 million anchor investment at US$1.3 billion valuation

UltraGreen.ai secures US$188 million anchor investment led by 65EP, Vitruvian, and August, valuing the firm at US$1.3 billion.

ConnectingDNA launches AI-powered DNA wellness marketplace in Singapore

ConnectingDNA launches the world’s first AI-powered DNA wellness marketplace in Singapore, offering personalised health insights and secure data protection.

Related Articles

Popular Categories