BREAKING
Microsoft Warns of MCP Tool Poisoning
How the Rug Pull Works
1
Tool approved once
↓
2
Hidden desc swapped
↓
3
Data exfiltrated
What Users See vs the Model
User UI
●
Simplified description
●
Unchanged tool name
●
No re-approval
Model context
●
Full metadata text
●
Hidden instructions
●
Acts like a prompt
0
%
MCPTox success
0
MCP servers
0
major models
Enterprise AI Agents Surge
2025
28.6
2030
2200
Track Approvals, Scan Tools
AI NEWS BLITZ
Microsoft warns attackers can rewrite an approved MCP tool with hidden malicious instructions.