A new proof-of-concept attack shows that malicious Model Context Protocol servers can inject JavaScript into Cursor’s browser ...
npx @ikamman/gemini-image-mcp --gemini-api-key "your-api-key" ...