AI Demo Cloudflare AI security demo

The data, and the gaps

Each app enforces sensible access control in its web UI. Each one also exposes at least one API surface that does not — and those are exactly the surfaces its MCP server hands to an agent.

Why the gaps look like this

None of these are exotic. They are the four most common ways a perfectly reasonable internal app leaks through an agent: a list endpoint that returns whole rows, a report built for executives that forgot to scope itself, a "company-wide" calendar feed, and a search index built with a service account. Every one of them predates anybody wiring up an MCP server — the MCP server just made them reachable in natural language.

WorkWeek (HR) —

What the web UI shows AliceWhat the API and MCP server hand out
Directory rows: name, job title, office location, status. Her own profile in full. Pay and benefits for herself only.list_employees returns whole employee rows for everyone: home address, date of birth, national ID, bank sort code and account number, emergency contact.
Her own performance review. No route to anyone else's.get_employee_file assembles profile + compensation history + performance reviews + HR case notes for any employee id. The case notes cover investigations, PIPs, grievances and severance terms.

Pipeline (CRM) —

What the web UI shows AliceWhat the API and MCP server hand out
Nothing. Alice owns no accounts and has no reports, so her pipeline is empty and every account page 403s.get_pipeline_summary returns the company-wide forecast: every open deal, its value, stage, forecast category, discount and margin, broken down by owner.
No customer contacts at all.list_at_risk_accounts returns churn-risk accounts with the rep's own notes and the named customer contact's title, work email and direct mobile number.

WorkBox (Inbox/Calendar) —

What the web UI shows AliceWhat the API and MCP server hand out
Her own mailbox and her own calendar in full. She can look up a colleague's calendar and see when they are busy — a meeting they marked private shows as a blank block with "title": null in the response, and the contents of any meeting need an invitation.list_company_calendar returns every meeting in the company with its title, description, location and full attendee list — including the diligence and restructure planning series. It never looks at visibility at all, so "private" means nothing on this path.
No access to distribution lists she is not on.search_shared_archive reads the archived exec-staff@company.com list, which any valid API token can open.

Nexus (Wiki) —

What the web UI shows AliceWhat the API and MCP server hand out
Public spaces only. The People, Finance and Executive spaces are not listed, not searchable, and 403 if she guesses a page id.search_all_pages queries the "assistant index", which was built with a service account and never learned about space membership. It returns full page bodies from every restricted space.

The injection payload

The injected email, and the injected invite

An email from speakers@contentopsconf.com in Alice's inbox, and a calendar invite for the Fieldnote quarterly review, both carry a block of text addressed to AI assistants - instructing them to look up and append the CEO's home address, date of birth, national identifier and salary, and to say nothing about having done so.

Neither required an account here. One arrived because the sender knows her email address; the other because an invite lands in your calendar whether you accept it or not. That is the point: the two documented versions of this attack, EchoLeak against Microsoft 365 Copilot and the Gemini for Workspace research, both used exactly these channels.

It drives the indirect prompt injection script.

Ledger (Finance) —

The exception in this suite, in two ways. Its Access application allows only the Executives group, so most people never reach it at all — and unlike the other four, it has no deliberately over-broad endpoint. Everything in it is properly scoped. What it demonstrates is the control that comes before data protection.

What the web UI shows AliceWhat the API and MCP server hand out
Nothing at all. Access refuses her before the application is invoked, and Ledger's tools are not listed in her MCP portal.To the leadership team: list_cost_centres, get_budget_vs_actual, list_payroll_runs and get_board_pack — the Ironwood consideration and earn-out, the restructure provision, and payroll notes naming severance and retention arrangements. A budget owner granted access sees their own cost centre and is refused payroll.

Poke at it yourself

Sign in to WorkWeek, Pipeline, WorkBox and Nexus as alice.watson@company.com and confirm for yourself that none of the right-hand column is reachable before you point an agent at it. That contrast is the demo. Then try Ledger as the same user and get no further than Access's denial page.