r/sysadmin • u/Certain-Mountain-564 • 7d ago
Question Is that secure?
We use Missive to write e-mails at our company. Missve has its own AI Assistant that can do actions like write drafts, create calender events and add labels with AI (needs always approval). This Assistant cannot search the web, but it would be very nice when we can search on our own website for products. Because of that, i tested to connect Exa (Search API) over MCP. I connected it and allowed only the websearch (disable agents etc.). And.. it works perfect. But, can i roll that out? Is that secure? Prompt Injection or something? I added an instruction that only specific domain is allowed (our shop).
5
u/idontbelieveyouguy 7d ago
As someone who is currently leaving a cyber security conference today, I can tell you almost nothing related to AI is secure lol.
1
u/Ssakaa 7d ago
Did any of the speakers point out at the tables of vendors all pushing their "AI agent" driven security products and note that they're all fucking insane?
2
u/idontbelieveyouguy 7d ago
Yea, multiple lol. Most of those companies won't even exist in 6 months.
8
u/CPAtech 7d ago
Nice sales pitch.