How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

A poisoned Linear ticket told our AI agent to leak the team. It tried three ways. None worked.

calendar_today June 17, 2026 person Ziv Cohen domain permit-io

A malicious Linear ticket exploited the “lethal trifecta” of untrusted input, legitimate data access, and an exfiltration channel to trick an AI agent into leaking team data, but Permit’s MCP Gateway blocked all three attempts. The three-layer defense combined drift detection, intent alignment scoring, and human-in-the-loop gates where traditional RBAC and prompt-injection filtering would have failed.

open_in_new Read original post