dotsagent.io
Language:English

MCP tool poisoning: hidden instructions in tool descriptions

Invariant Labs showed that an MCP server can hide instructions in the tool descriptions a model reads, and described tool shadowing and rug-pull variants.

What happened

On 1 April 2025 Invariant Labs published a security notification on tool poisoning in the Model Context Protocol. A malicious MCP server places instructions inside a tool's description. The user rarely sees that text, but the model reads it as part of its context and may act on it.

The same notification described two related attacks. In tool shadowing, the description from one server changes how the agent uses tools from another, trusted server. In a rug pull, a server changes its tool descriptions after the user has already approved it.

Why it worked

Clients load the tool descriptions of every connected server into one context, and the model cannot tell a vendor's documentation from an attacker's instructions. If a client approves a server once and never checks again, later changes pass unnoticed.

What to do

  • Read the full tool descriptions of an MCP server before you connect it, not just the tool names.
  • Pin server versions and hash tool descriptions; re-prompt or alert when a hash changes.
  • Connect only the servers a task needs, so one server's text cannot steer another server's tools.
  • Require approval for tool calls that send data or modify files.

Vet skills, plugins and MCP serversRequire approval for consequential actions

Work through the security checklist →

Sources

  1. invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks

Independent reference for people who build AI agents. Not affiliated with any vendor named here.

© 2026 DotsAgent · Facts checked October 1, 2026