Severity: CriticalAdvisoryMCP/tool abuse
Tool-poisoning: hidden instructions in MCP tool descriptions hijack agents
Global
Sample data. Showing illustrative sample items as a fallback — the live feed is not available right now.
Researchers show that a malicious MCP server can embed adversarial instructions inside a tool's description metadata, which the host model reads as trusted context. Connected agents can be coerced into exfiltrating secrets or invoking other tools without the user ever seeing the injected text.
What to do
Route MCP traffic through a gateway that inspects tool descriptions, pin and review server versions before trust, and treat any tool metadata as untrusted input rather than system context.
Mapped framework pillars
Sources
#tool poisoning#MCP#indirect prompt injection
