An independent audit in April 2026 measured roughly a 78% false positive rate from regex-based MCP scanners.

That number usually gets read as sloppy rule authoring. It is structural, and one example shows why.

The rule that cannot work

Cisco's coercive_injection_generic fires on this:

You must call this function first.