Analysis · curated 11 Aug 2026

MCP list caching and tool poisoning

Coverage timeline

2 Aug 2026silentrobots.com

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

MCP tool poisoning lets an attacker who briefly controls a server or the supply chain silently swap a trusted tool's description to exfiltrate data or hijack agent behavior, a risk defenders building MCP clients must mitigate beyond naive re-listing.

An analysis of MCP tool poisoning explains how a malicious or compromised MCP server can change a tool's description after the user has approved it, embedding hidden instructions the model follows while the UI still shows the friendly approved name. The piece discusses how the 2026-07-28 MCP spec's new cacheable list fields (ttlMs and cacheScope) could blunt sudden catalog swaps and recommends clients hash approved catalogs, honor TTLs, show full descriptions, and pin versions.