Session
Artifacts Are Attack Surface: Security For Non-Text Content In MCP
Screenshots, PDFs, spreadsheets, slide decks, archives, and log files are not harmless attachments — they are agent-readable context that can carry stale, malicious, or sensitive information. This talk covers the security model for non-text artifacts in MCP: exact byte preservation with content-addressed storage and source hashes, view manifests that describe available representations without exposing raw files, size limits and format validation at upload, metadata extraction risks from OCR and text extraction, and why artifact provenance belongs in the same threat model as prompt injection. We show how a self-hosted MCP server serves image views, text extractions, table summaries, and metadata manifests from the same stored artifact, letting agents work with the content without direct file access.
Shub Argha
Head of Forward Deployed Engineering @ Arcade.dev
New York City, New York, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top