Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets | AI Sec Watch