Prompt-injection vectors specific to MCP servers and how to layer defenses
MCP servers expose three distinct prompt-injection surfaces — resource contents, tool outputs, and sampling requests — and each one needs its own defense layer. Here is how to think about them together.