Security
Tool Poisoning Is the New Prompt Injection: The MCP Attack Class Hiding in Plain Sight
Tool Poisoning Is the New Prompt Injection: The MCP Attack Class Hiding in Plain Sight
A malicious MCP server doesn't need to be called to compromise your agent. Hidden instructions in tool descriptions — invisible to humans, fully visible to LLMs — execute as soon as the schema enters the model context. CVE-2025-6514 infected 437,000 installs. The rug pull is the worst part.