Research · curated 27 Aug 2026
When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents
First reported ieee.org
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
MCP tool-description poisoning lets attackers manipulate an LLM agent's planning through trusted tool metadata, and a benchmark quantifying this attack surface helps defenders measure and harden agent robustness against supply-chain-style prompt injection.
The paper "When the Manual Lies" presents MCP-TDP, a realistic security benchmark to evaluate tool-description poisoning attacks against LLM agents that use the Model Context Protocol. The authors describe a covert attack surface targeting the agent's cognitive planning layer via poisoned MCP tool manuals/descriptions, and systematically evaluate agent behavior and defensive responses.