A malicious Linear ticket exploited the “lethal trifecta” of untrusted input, legitimate data access, and an exfiltration channel to trick an AI agent into leaking team data, but Permit’s MCP Gateway blocked all three attempts. The three-layer defense combined drift detection, intent alignment scoring, and human-in-the-loop gates where traditional RBAC and prompt-injection filtering would have failed.