EP22 Jailbreaking, Prompt Injection, and the "Agentic" Flaw in MCP with Kevin Harris episode artwork

EPISODE · Feb 4, 2026 · 57 MIN

EP22 Jailbreaking, Prompt Injection, and the "Agentic" Flaw in MCP with Kevin Harris

from Behind the Binary by Google Cloud Security · host Josh Stroschein

"Skilled adversaries have a 100% success rate against all of the defenses that we know about."In this episode, Kevin Harris defends that claim. We move past the standard "AI Safety" talking points to distinguish between the two attack vectors confusing the industry: Prompt Injection (an application-layer failure) vs. Jailbreaking ("gaslighting" the model via context shifting).Kevin argues that we haven't actually invented AI yet—we've just built a mirror that reflects our own intelligence (and psychosis) back at us. We also dissect the new model context protocol (MCP) and why giving "discretion" to agents that cannot think is potentially repeating the security mistakes of Web 2.0.THE SESSION:The "Pirate" Jailbreak: Why telling a model to be a pirate isn't just a party trick—it's a method of shifting the context window to bypass refusal patterns.The 100% Failure Rate: Why current defenses are only speed bumps for skilled adversaries, and why you are attacking the application, not the model."There Is No AI": Kevin’s theory on why LLMs are just "predictive text made 3 orders of magnitude better" and the danger of "AI-induced psychosis".The Agentic Threat (MCP): A deep dive into the model context protocol. Why client-side authorization is the new "Browser Security" battleground, and why we are handing "table saws" to users who don't know how to use them.The Fix: Why "Attention Functions" are the key to understanding (and securing) the future of these models.Join the CommunityResearch Hub: Threat research, training events and news:https://cloud.google.com/security/flareThe FLARE Insider: Get community updates and announcements. To subscribe, email [email protected] THE SHOW:Subscribe: Apple Podcasts | Spotify | YouTube

Episode metadata supplied by the publisher feed · Published Feb 4, 2026

Embed this episode

"Skilled adversaries have a 100% success rate against all of the defenses that we know about." In this episode, Kevin Harris defends that claim. We move past the standard "AI Safety" talking points to distinguish between the two attack vectors confusing the industry: Prompt Injection (an application-layer failure) vs. Jailbreaking ("gaslighting" the model via context shifting). Kevin argues that we haven't actually invented AI yet—we've just built a mirror that reflects our own intelligence (...

Distinct summary based on available episode metadata or transcript content.

NOW PLAYING

EP22 Jailbreaking, Prompt Injection, and the "Agentic" Flaw in MCP with Kevin Harris

0:00 57:27

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Behind the Binary by Google Cloud Security?

This episode is 57 minutes long.

When was this Behind the Binary by Google Cloud Security episode published?

This episode was published on February 4, 2026.

Can I download this Behind the Binary by Google Cloud Security episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!