<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>MCP Client on Vivian@SecMomBag</title><link>https://vvnblog.com/en/tags/mcp-client/</link><description>Recent content in MCP Client on Vivian@SecMomBag</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>Copyright © 2026 Vivian All Rights Reserved.</copyright><lastBuildDate>Sun, 06 Sep 2026 00:00:00 +0800</lastBuildDate><atom:link href="https://vvnblog.com/en/tags/mcp-client/index.xml" rel="self" type="application/rss+xml"/><item><title>AI Dark Arts (18): Approve Once, Trust Forever? The MCP Client Attack Surface</title><link>https://vvnblog.com/en/posts/ai-dark-arts-18/</link><pubDate>Sun, 06 Sep 2026 00:00:00 +0800</pubDate><guid>https://vvnblog.com/en/posts/ai-dark-arts-18/</guid><description>Does approving a config file once mean trusting it forever? From MCPoison and CurXecute to mcp-remote and MCP Inspector, this is how the client side of MCP gets attacked.</description></item></channel></rss>