The increasing reliance on AI coding assistants, software that helps developers write, debug, and refactor code, introduces critical security vulnerabilities, notably Data Poisoning and Prompt Injection. This article, targeted at professional developers and researchers, dives into these attack vectors within the context of the Model Context Protocol (MCP), a standardized framework for enabling secure, tool-based interactions. We explore specific MCP-centric attacks, such as tool description manipulation and context-aware injection.