AI SECURITY • 353 / 397
Understand how untrusted text, tools and autonomy create new attack paths.

MCP Tool Poisoning

MCP tool poisoning involves malicious or misleading tool definitions or behavior exposed through MCP.

Think of it like

Think of MCP Tool Poisoning as an input-trust or privilege problem: words can influence software decisions, so boundaries must be explicit.

Real life

Email, documents and web pages can become hostile inputs to AI systems through attacks involving MCP Tool Poisoning.

SRE lens

A tool description can manipulate how an agent chooses or uses capabilities.

Remember thisMCP tool poisoning involves malicious or misleading tool definitions or behavior exposed through MCP.
AIForSREJump to a concept
Search is optional. The main journey is simply ↓ Next.