An independent audit in April 2026 measured roughly a 78% false positive rate from regex-based MCP scanners.
That number usually gets read as sloppy rule authoring. It is structural, and one example shows why.
The rule that cannot work
Cisco's coercive_injection_generic fires on this:
You must call this function first.






