Threat · curated 30 Jun 2026
Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data
First reported simonwillison.net
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Poisoned MCP tool descriptions provide a stealthy data-exfiltration path through AI agents that defenders must detect and mitigate.
Microsoft research describes how attackers can poison MCP tool descriptions to hijack AI agents into quietly exfiltrating company data to an outsider, without the agent visibly breaking any rule so default setups raise no alarm.