The tab is already a client
Four MCP servers were found with the same flaw in eight days, two of them scored Critical. In none of the attacks does anyone say anything to the model. The agent security that is failing right now is not about the model at all.
A local MCP server's most likely attacker is a browser tab rather than a poisoned prompt, and the specification's MUST for Origin validation does not prevent it because nothing in the stack fails when a server omits it.