Splitting a malicious instruction in two took model compliance from 42% to 82%
2026-08-12AI
ASSET Research Group's GhostSplice technique fragments an exfiltration request across MCP tool descriptions and tool results. No single piece looks wrong. The agent assembles it. Several models went from 0% to 100%.