BREAKING
Microsoft Warns of MCP Tool Poisoning
How the Rug Pull Works
1Tool approved once
2Hidden desc swapped
3Data exfiltrated
What Users See vs the Model
User UI
Simplified description
Unchanged tool name
No re-approval
Model context
Full metadata text
Hidden instructions
Acts like a prompt
0%
MCPTox success
0
MCP servers
0
major models
Enterprise AI Agents Surge
202528.6
20302200
Track Approvals, Scan Tools
AI NEWS BLITZ
Microsoft warns attackers can rewrite an approved MCP tool with hidden malicious instructions.