Research · curated 27 Aug 2026

When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents

Coverage timeline

27 Aug 2026ieee.org

Single-source research — first reported, latest, and curated coincide.

Why it matters

MCP tool-description poisoning lets attackers manipulate an LLM agent's planning through trusted tool metadata, and a benchmark quantifying this attack surface helps defenders measure and harden agent robustness against supply-chain-style prompt injection.

The paper "When the Manual Lies" presents MCP-TDP, a realistic security benchmark to evaluate tool-description poisoning attacks against LLM agents that use the Model Context Protocol. The authors describe a covert attack surface targeting the agent's cognitive planning layer via poisoned MCP tool manuals/descriptions, and systematically evaluate agent behavior and defensive responses.