Testing KiroCrew's security posture against prompt injection via a malicious MCP server. Both direct credential access and multi-stage exfiltration attempts were blocked by intent-level detection — a significant step up from previous tests.