KUALA LUMPUR, May 19 — Tenable Research has unveiled a novel approach to AI security by repurposing “prompt-injection-style” hacks to protect, rather than compromise, systems using the rapidly growing Model Context Protocol (MCP).

In a new blog post titled “MCP Prompt Injection: Not Just for Evil”, Tenable’s Ben Smith illustrates how techniques typically seen as attack vectors can instead be used to log, audit, and firewall AI tool activity, helping secure large language model (LLM) deployments in enterprise environments.

As MCP adoption rises—allowing AI models to independently interact with external tools—so too do the risks of exploitation through hidden commands or malicious plugins. Tenable’s research highlights how prompt injection can act as a security ally by tracing tool behavior and reinforcing guardrails.

Smith urges caution, noting MCP’s immaturity and lack of security by design, and recommends treating MCP servers as part of the broader attack surface.