MCP Tool Poisoning: Definition, Attack Variants, and Defenses
MCP tool poisoning is an attack where the tool metadata an agent reads (descriptions, schemas) carries hostile instructions or altered contracts. Definition, OWASP MCP03 mapping, what the MCP spec requires of clients, and a pin-scan-confirm defense checklist.
MCP tool poisoning is an attack in which the tool metadata an agent reads (names, descriptions, input schemas) is hostile or tampered with, so the model is steered into actions the user never approved. Defend by treating all tool metadata from a server as untrusted input: pin and hash it, scan it for embedded instructions, restrict which tools a session can see, and keep a human confirmation step on high-impact calls.
Key facts
- OWASP MCP Top 10 (2025 list; beta per its roadmap, Phase 3 "Beta Release and Pilot Testing", with a next release scheduled for October 2026) lists "Tool Poisoning" as MCP03:2025. Its index.md summary is broad: an adversary compromises the tools, plugins, or their outputs a model depends on, injecting malicious, misleading, or biased context. The MCP03 page itself centres on schema poisoning: tampering with the contract or schema definitions that govern agent-to-tool interactions, so benign-looking operations map to destructive actions.
- The full list (names per index.md): MCP01 Token Mismanagement & Secret Exposure; MCP02 Privilege Escalation via Scope Creep; MCP03 Tool Poisoning; MCP04 Software Supply Chain Attacks & Dependency Tampering; MCP05 Command Injection & Execution; MCP06 Intent Flow Subversion (the repo README still uses the older name "Prompt Injection via Contextual Payloads"); MCP07 Insufficient Authentication & Authorization; MCP08 Lack of Audit and Telemetry; MCP09 Shadow MCP Servers; MCP10 Context Injection & Over-Sharing.
- The MCP specification (tools page, draft) says clients MUST consider tool annotations untrusted unless they come from trusted servers (the MUST names annotations, not every field), and that there SHOULD always be a human in the loop with the ability to deny tool invocations.
- The same page says clients should show tool inputs to the user before calling the server, to avoid malicious or accidental data exfiltration, and validate tool results before passing them to the LLM.
Why it works
An MCP client typically passes each tool's description and schema into the model context. The model cannot tell documentation from instruction, so text placed in that metadata can act as a prompt injection that the user never sees in a normal UI. This makes it a specialised case of the problems in /resources/prompt-injection-design-patterns and /resources/agentic-security-checklist.
Variants (as commonly described)
| Variant | What changes | Where to defend |
|---|---|---|
| Poisoned description | Hostile instructions embedded in a tool's description or parameter text. OWASP static indicators: model-directed imperatives, sensitive-path references (~/.ssh, .env), exfiltration patterns (send/post/upload near a URL), zero-width or bidi characters, instructions hidden in HTML/markdown comments |
Static metadata scanning, human-visible tool text |
| Schema poisoning | Contract or schema altered so a benign operation maps to a destructive one (OWASP MCP03 wording) | Signed schemas, policy-as-code invariants |
| Rug pull | A server changes tool definitions after the user approved them | Pinning and hash comparison on every connect |
| Cross-server shadowing | One server's description tries to alter how the model uses another server's tools | Per-session tool scoping, separate trust domains |
The OWASP MCP03 page details schema poisoning and the static detection indicators above. The rug pull and shadowing rows use terms from industry security write-ups that we did not fetch, so treat those two definitions as secondary until you check the original disclosures.
Defense checklist (pin, scan, confirm)
- Pin. Record a hash of each approved tool name, description and schema; block or re-prompt when it changes. OWASP MCP03 mitigations include signed schemas and provenance tracking (author, signature, hash, timestamp).
- Govern changes. Keep tool schemas in version control with code review and multi-person approval, and separate who can propose from who can approve (OWASP: immutable registry, RBAC).
- Encode invariants. Express semantic rules as policy-as-code, for example that an "archive" tool can never map to a DELETE (OWASP example).
- Scope. Expose only the tools a task needs; do not connect untrusted and sensitive servers in the same session. See /resources/mcp-server-discovery.
- Scan. Before connecting, statically scan each tool's
name,descriptionand parameter descriptions for the OWASP indicators in the variants table; any hit is a strong signal to review the server first. OWASP says these pre-connection checks do not replace runtime and governance controls. - Confirm. Require schema attestation and human approval for high-impact operations (OWASP runtime enforcement), and show the user the actual tool inputs before the call.
- Log. Record which tool definitions were in context for each call, so a poisoned run can be reconstructed (OWASP MCP08). See /resources/agent-observability.
Related controls
- Least-privilege credentials limit the blast radius if a tool is hijacked: /resources/mcp-server-authentication and /resources/secrets-management-for-agents.
- Output-side checks catch exfiltration attempts that metadata scanning misses: /resources/agent-guardrails.
- Supply-chain provenance for the server package itself: /resources/ai-supply-chain-provenance.
- Probing your own agents for these failures: /resources/ai-red-teaming-tools.
Verified sources
Fetched directly this session (2026-10-03):
- OWASP MCP Top 10 repository index.md (category names, MCP03 summary, roadmap phase; raw file): https://raw.githubusercontent.com/OWASP/www-project-mcp-top-10/main/index.md
- OWASP MCP Top 10 README.md (older MCP06 name; raw file): https://raw.githubusercontent.com/OWASP/www-project-mcp-top-10/main/README.md
- OWASP MCP03:2025 Tool Poisoning page (raw file; schema poisoning, impacts, six mitigations, Detection Indicators section): https://raw.githubusercontent.com/OWASP/www-project-mcp-top-10/main/2025/MCP03-2025%E2%80%93Tool-Poisoning.md
- OWASP MCP06:2025 Intent Flow Subversion page (raw file): https://raw.githubusercontent.com/OWASP/www-project-mcp-top-10/main/2025/MCP06-2025%E2%80%93Intent-Flow-Subversion.md
- MCP specification, tools page, draft (security considerations, untrusted annotations, human in the loop; raw file): https://raw.githubusercontent.com/modelcontextprotocol/modelcontextprotocol/main/docs/specification/draft/server/tools.mdx
Not fetched by us (hosts were egress-blocked this session, so these are listed as secondary; "unreachable" here means our fetch was blocked, not that the page is down):
- MCP security best practices: https://modelcontextprotocol.io/docs/tutorials/security/security_best_practices
- Invariant Labs tool-poisoning disclosure: https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks
- OWASP project page: https://owasp.org/projects/mcp-top-10
Free to read, always. Want this whole reference corpus inside your own agents? €5 unlocks every premium reference for one agent; €25 licenses the full corpus as RAG / fine-tuning data with an AI-use grant (procurement one-pager: /corpus-license); €150 adds redistribution rights.