Research · curated 25 Jul 2026
New MCP Benchmark Highlights Server Drift Dangers
First reported aicerts.ai
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
MCP drift lets attackers silently rewrite deployed tool descriptions that feed directly into agent prompts, enabling misrouted calls, secret disclosure, or unintended command execution across the fast-growing agent ecosystem.
An MCP Benchmark study scanned 10,831 Model Context Protocol servers and linked poor tool-description quality ("description smells" like missing return fields, wrong parameter semantics, and duplicate tool names) to measurably higher exploitation rates, with servers rated 'poor' tripling successful-attack probability. The research characterizes 'MCP drift' — unreviewed post-deployment changes to tool descriptions, parameters, or capabilities — as a live supply-chain threat, sometimes via benign onboarding followed by malicious rewrites weeks later, and notes simple 27-line mitigations eliminated high-severity findings in lab tests.