Skip to content

MCP tool poisoning attacks (2025)

Reference

Citation: Invariant Labs. "MCP tool poisoning attacks" (1 Apr 2025). Type: report. Link: invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks.

What it is

A security notification describing tool poisoning attacks against the Model Context Protocol. It documents how a tool description can carry hidden instructions.

Role in the record

  • Grounds BP03: a poisoned tool description hides instructions from the user; the rug-pull variant mutates a tool after approval.

Atom-level for/against detail and quotes are in the provenance data (assets/provenance.yml), keyed by practice atom.

Discussion