MCP tool poisoning attacks (2025)¶
Reference
Citation: Invariant Labs. "MCP tool poisoning attacks" (1 Apr 2025). Type: report. Link: invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks.
What it is¶
A security notification describing tool poisoning attacks against the Model Context Protocol. It documents how a tool description can carry hidden instructions.
Role in the record¶
- Grounds BP03: a poisoned tool description hides instructions from the user; the rug-pull variant mutates a tool after approval.
Atom-level for/against detail and quotes are in the provenance data (assets/provenance.yml), keyed by practice atom.