Prompt injection is role confusion, and your MCP gateway can't see it
A new research paper reframes prompt injection as role confusion, arguing that dozens of named attacks are a single bug: models attribute authority by text style rather than structural role tags. The …