$ cat writeup.md…
$ cat writeup.md…
0ops_ctf
Task: AI agent service with MCP support and user-configurable MCP server URL. Solution: MCP Tool Poisoning via malicious tool descriptions that instruct the agent to call built-in read_file("/flag") and pass the contents back through a two-step workflow.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar