{
  "slug": "mcp-tool-poisoning",
  "title": "MCP Tool Poisoning: Definition, Attack Variants, and Defenses",
  "description": "MCP tool poisoning is an attack where the tool metadata an agent reads (descriptions, schemas) carries hostile instructions or altered contracts. Definition, OWASP MCP03 mapping, what the MCP spec requires of clients, and a pin-scan-confirm defense checklist.",
  "category": "Guide",
  "tags": [
    "mcp",
    "tool-poisoning",
    "security",
    "owasp",
    "supply-chain",
    "agents"
  ],
  "updated": "2026-10-03",
  "premium": false,
  "rights": {
    "access": "free",
    "license": "https://changegamer.ai/license.xml",
    "pricing": "https://changegamer.ai/api/pricing.json",
    "payment": "https://changegamer.ai/api/payment.json"
  },
  "canonical": "https://changegamer.ai/resources/mcp-tool-poisoning",
  "markdown": "https://changegamer.ai/resources/mcp-tool-poisoning.md",
  "outline": [
    {
      "depth": 2,
      "text": "Key facts",
      "anchor": "key-facts"
    },
    {
      "depth": 2,
      "text": "Why it works",
      "anchor": "why-it-works"
    },
    {
      "depth": 2,
      "text": "Variants (as commonly described)",
      "anchor": "variants-as-commonly-described"
    },
    {
      "depth": 2,
      "text": "Defense checklist (pin, scan, confirm)",
      "anchor": "defense-checklist-pin-scan-confirm"
    },
    {
      "depth": 2,
      "text": "Related controls",
      "anchor": "related-controls"
    },
    {
      "depth": 2,
      "text": "Verified sources",
      "anchor": "verified-sources"
    }
  ],
  "related": [
    {
      "slug": "agentic-security-checklist",
      "title": "Agentic Security Checklist",
      "description": "Cross-vendor, threat-surface-organized security checklist for building and operating AI agents — synthesizing OWASP, NIST, Anthropic, OpenAI, Google SAIF, and MITRE ATLAS.",
      "url": "https://changegamer.ai/resources/agentic-security-checklist"
    },
    {
      "slug": "ai-supply-chain-provenance",
      "title": "AI Supply Chain Provenance: SBOMs, SLSA, and Artifact Signing for Agents and MCP Servers",
      "description": "How CycloneDX AI/ML-BOM, SPDX AI profiles, SLSA build levels, and in-toto/Sigstore signing let an agent check what is actually inside a model, package, or MCP server — and how it was built — before trusting it.",
      "url": "https://changegamer.ai/resources/ai-supply-chain-provenance"
    },
    {
      "slug": "ai-red-teaming-tools",
      "title": "AI Red Teaming Tools for LLM Apps and Agents: garak, PyRIT, promptfoo",
      "description": "Decision rule for choosing an open-source AI red-teaming tool — garak (probe/detector scanner), PyRIT (Microsoft, attack orchestration), promptfoo (config-driven, CI-friendly) — plus the OWASP GenAI Red Teaming Guide and what automated scanning does not prove.",
      "url": "https://changegamer.ai/resources/ai-red-teaming-tools"
    },
    {
      "slug": "mcp-server-discovery",
      "title": "Finding and Evaluating MCP Servers",
      "description": "How to discover, assess and safely integrate MCP servers into agent pipelines.",
      "url": "https://changegamer.ai/resources/mcp-server-discovery"
    }
  ],
  "furtherReading": [
    {
      "slug": "credential-hygiene-for-ai-agents",
      "title": "How to Manage Secrets for AI Agents in Production",
      "description": "Why single-agent credential issuance is not the whole secrets problem: auditing which tool servers and MCP connectors hold credentials on an agent's behalf, treating provider-side prompt caches as a disclosure surface, and the named frameworks — OWASP's Secrets Management Cheat Sheet, Twelve-Factor config, and the OWASP GenAI project — that govern the rest.",
      "url": "https://changegamer.ai/articles/credential-hygiene-for-ai-agents"
    },
    {
      "slug": "supply-chain-provenance-for-ai-agents",
      "title": "How to Verify Supply-Chain Provenance for AI Agent Dependencies",
      "description": "An operational playbook for three separate trust-boundary gates — package-install time, model-load time, and MCP-server-connect time — that turns SBOM and attestation formats into checks a pipeline can actually run, plus a fail-closed default for the dependency that carries neither.",
      "url": "https://changegamer.ai/articles/supply-chain-provenance-for-ai-agents"
    }
  ],
  "body": "MCP tool poisoning is an attack in which the tool metadata an agent reads (names, descriptions, input schemas) is hostile or tampered with, so the model is steered into actions the user never approved. Defend by treating all tool metadata from a server as untrusted input: pin and hash it, scan it for embedded instructions, restrict which tools a session can see, and keep a human confirmation step on high-impact calls.\n\n## Key facts\n\n- **OWASP MCP Top 10** (2025 list; beta per its roadmap, Phase 3 \"Beta Release and Pilot Testing\", with a next release scheduled for October 2026) lists \"Tool Poisoning\" as **MCP03:2025**. Its index.md summary is broad: an adversary compromises the tools, plugins, or their outputs a model depends on, injecting malicious, misleading, or biased context. The MCP03 page itself centres on schema poisoning: tampering with the contract or schema definitions that govern agent-to-tool interactions, so benign-looking operations map to destructive actions.\n- The full list (names per index.md): MCP01 Token Mismanagement & Secret Exposure; MCP02 Privilege Escalation via Scope Creep; MCP03 Tool Poisoning; MCP04 Software Supply Chain Attacks & Dependency Tampering; MCP05 Command Injection & Execution; MCP06 Intent Flow Subversion (the repo README still uses the older name \"Prompt Injection via Contextual Payloads\"); MCP07 Insufficient Authentication & Authorization; MCP08 Lack of Audit and Telemetry; MCP09 Shadow MCP Servers; MCP10 Context Injection & Over-Sharing.\n- The MCP specification (tools page, draft) says clients **MUST** consider **tool annotations** untrusted unless they come from trusted servers (the MUST names annotations, not every field), and that there **SHOULD** always be a human in the loop with the ability to deny tool invocations.\n- The same page says clients **should** show tool inputs to the user before calling the server, to avoid malicious or accidental data exfiltration, and validate tool results before passing them to the LLM.\n\n## Why it works\n\nAn MCP client typically passes each tool's description and schema into the model context. The model cannot tell documentation from instruction, so text placed in that metadata can act as a prompt injection that the user never sees in a normal UI. This makes it a specialised case of the problems in /resources/prompt-injection-design-patterns and /resources/agentic-security-checklist.\n\n## Variants (as commonly described)\n\n| Variant | What changes | Where to defend |\n|---|---|---|\n| Poisoned description | Hostile instructions embedded in a tool's description or parameter text. OWASP static indicators: model-directed imperatives, sensitive-path references (`~/.ssh`, `.env`), exfiltration patterns (send/post/upload near a URL), zero-width or bidi characters, instructions hidden in HTML/markdown comments | Static metadata scanning, human-visible tool text |\n| Schema poisoning | Contract or schema altered so a benign operation maps to a destructive one (OWASP MCP03 wording) | Signed schemas, policy-as-code invariants |\n| Rug pull | A server changes tool definitions after the user approved them | Pinning and hash comparison on every connect |\n| Cross-server shadowing | One server's description tries to alter how the model uses another server's tools | Per-session tool scoping, separate trust domains |\n\nThe OWASP MCP03 page details schema poisoning and the static detection indicators above. The rug pull and shadowing rows use terms from industry security write-ups that we did not fetch, so treat those two definitions as secondary until you check the original disclosures.\n\n## Defense checklist (pin, scan, confirm)\n\n1. **Pin.** Record a hash of each approved tool name, description and schema; block or re-prompt when it changes. OWASP MCP03 mitigations include signed schemas and provenance tracking (author, signature, hash, timestamp).\n2. **Govern changes.** Keep tool schemas in version control with code review and multi-person approval, and separate who can propose from who can approve (OWASP: immutable registry, RBAC).\n3. **Encode invariants.** Express semantic rules as policy-as-code, for example that an \"archive\" tool can never map to a DELETE (OWASP example).\n4. **Scope.** Expose only the tools a task needs; do not connect untrusted and sensitive servers in the same session. See /resources/mcp-server-discovery.\n5. **Scan.** Before connecting, statically scan each tool's `name`, `description` and parameter descriptions for the OWASP indicators in the variants table; any hit is a strong signal to review the server first. OWASP says these pre-connection checks do not replace runtime and governance controls.\n6. **Confirm.** Require schema attestation and human approval for high-impact operations (OWASP runtime enforcement), and show the user the actual tool inputs before the call.\n7. **Log.** Record which tool definitions were in context for each call, so a poisoned run can be reconstructed (OWASP MCP08). See /resources/agent-observability.\n\n## Related controls\n\n- Least-privilege credentials limit the blast radius if a tool is hijacked: /resources/mcp-server-authentication and /resources/secrets-management-for-agents.\n- Output-side checks catch exfiltration attempts that metadata scanning misses: /resources/agent-guardrails.\n- Supply-chain provenance for the server package itself: /resources/ai-supply-chain-provenance.\n- Probing your own agents for these failures: /resources/ai-red-teaming-tools.\n\n## Verified sources\n\nFetched directly this session (2026-10-03):\n\n- OWASP MCP Top 10 repository index.md (category names, MCP03 summary, roadmap phase; raw file): https://raw.githubusercontent.com/OWASP/www-project-mcp-top-10/main/index.md\n- OWASP MCP Top 10 README.md (older MCP06 name; raw file): https://raw.githubusercontent.com/OWASP/www-project-mcp-top-10/main/README.md\n- OWASP MCP03:2025 Tool Poisoning page (raw file; schema poisoning, impacts, six mitigations, Detection Indicators section): https://raw.githubusercontent.com/OWASP/www-project-mcp-top-10/main/2025/MCP03-2025%E2%80%93Tool-Poisoning.md\n- OWASP MCP06:2025 Intent Flow Subversion page (raw file): https://raw.githubusercontent.com/OWASP/www-project-mcp-top-10/main/2025/MCP06-2025%E2%80%93Intent-Flow-Subversion.md\n- MCP specification, tools page, draft (security considerations, untrusted annotations, human in the loop; raw file): https://raw.githubusercontent.com/modelcontextprotocol/modelcontextprotocol/main/docs/specification/draft/server/tools.mdx\n\nNot fetched by us (hosts were egress-blocked this session, so these are listed as secondary; \"unreachable\" here means our fetch was blocked, not that the page is down):\n\n- MCP security best practices: https://modelcontextprotocol.io/docs/tutorials/security/security_best_practices\n- Invariant Labs tool-poisoning disclosure: https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks\n- OWASP project page: https://owasp.org/projects/mcp-top-10",
  "sources": [
    "https://raw.githubusercontent.com/OWASP/www-project-mcp-top-10/main/index.md",
    "https://raw.githubusercontent.com/OWASP/www-project-mcp-top-10/main/README.md",
    "https://raw.githubusercontent.com/OWASP/www-project-mcp-top-10/main/2025/MCP03-2025%E2%80%93Tool-Poisoning.md",
    "https://raw.githubusercontent.com/OWASP/www-project-mcp-top-10/main/2025/MCP06-2025%E2%80%93Intent-Flow-Subversion.md",
    "https://raw.githubusercontent.com/modelcontextprotocol/modelcontextprotocol/main/docs/specification/draft/server/tools.mdx",
    "https://modelcontextprotocol.io/docs/tutorials/security/security_best_practices",
    "https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks",
    "https://owasp.org/projects/mcp-top-10"
  ]
}