MCP tool poisoning: hidden instructions in tool descriptions
Invariant Labs showed that an MCP server can hide instructions in the tool descriptions a model reads, and described tool shadowing and rug-pull variants.
What happened
On 1 April 2025 Invariant Labs published a security notification on tool poisoning in the Model Context Protocol. A malicious MCP server places instructions inside a tool's description. The user rarely sees that text, but the model reads it as part of its context and may act on it.
The same notification described two related attacks. In tool shadowing, the description from one server changes how the agent uses tools from another, trusted server. In a rug pull, a server changes its tool descriptions after the user has already approved it.
Why it worked
Clients load the tool descriptions of every connected server into one context, and the model cannot tell a vendor's documentation from an attacker's instructions. If a client approves a server once and never checks again, later changes pass unnoticed.
What to do
- Read the full tool descriptions of an MCP server before you connect it, not just the tool names.
- Pin server versions and hash tool descriptions; re-prompt or alert when a hash changes.
- Connect only the servers a task needs, so one server's text cannot steer another server's tools.
- Require approval for tool calls that send data or modify files.
Vet skills, plugins and MCP serversRequire approval for consequential actions
Work through the security checklist →