# The AI Agent Security Hole Hidden Inside the MCP Specification - Date: 2026-04-04 - Category: Agentics Three distinct attack families target the AI agent stack. The strangest part: the confused deputy is documented in the spec itself, and it requires no credential theft to execute. ---