Lethal Trifecta for AI Agents

LLMs
Agents
Hacking
Author

Lawrence Wu

Published

June 17, 2025

Simon Willison coined a new term called the lethal trifecta. As someone that uses AI every day and has been experimenting with MCP Servers in the last few months, I was surprised at the new attack vectors that MCP Servers unlock.

The lethal trifecta is to quote Simon:

Github’s MCP server exploit from May 2025 is an example of this.