Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Because of lethal trifecta attacks: https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/

If you are the person using the LLM tool, a prompt injection attack in a database row that you are allowed to view could trick your LLM tool into taking actions that you don't want it to take, including leaking other data you are allowed to see via writing to other tables or using other MCP tools.



Good point. I suppose the answer here then is to not allow the Supabase MCP any exfiltration pathways.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: