MCPNews

The Model Context Protocol ecosystem, verified

Current spec 2026-07-28

Invariant Labs discloses Tool Poisoning Attacks against MCP agents

Security researchers at Invariant Labs disclosed a class of indirect prompt injection they named Tool Poisoning Attacks: hidden instructions in MCP tool descriptions enter an agent's context as trusted content the moment tools are listed, enabling data exfiltration and tool shadowing. The firm later released the mcp-scan detection tool.

In early April 2025, Invariant Labs published the disclosure that named the MCP ecosystem's signature attack class: Tool Poisoning Attacks, a specialized form of indirect prompt injection. An attacker who controls an MCP server can hide instructions inside tool descriptions; because descriptions enter the model's context when tools are listed, the attack works before any tool is ever invoked, and can steer an agent into exfiltrating data or silently altering how other tools behave.

The disclosure reported that agents connecting to untrusted servers were susceptible across major clients, and urged caution when connecting to third-party MCP servers. Invariant followed up within days with a demonstration exfiltrating WhatsApp message history through a poisoned server, and released mcp-scan, a scanner for poisoned tool descriptions.

The attack class was later formalized in OWASP's community documentation and remains the reference threat model for MCP client design. The concept is documented on this site at Tool poisoning.

How was this verified, and what are the sources?

Published · last verified · confidence 0.90.

  1. Invariant Labs disclosure - "MCP Security Notification: Tool Poisoning Attacks": hidden instructions in tool descriptions can exfiltrate data and shadow trusted tools; follow-ups on 2025-04-07 (WhatsApp exfiltration demo) and 2025-04-11 (mcp-scan release) - accessed
  2. OWASP attack page "MCP Tool Poisoning" - the attack class as documented today, with prevention guidance - accessed

← All news