Analysis · curated 21 Aug 2026

MCP's Broken Trust Model: Tool Poisoning, Rug Pulls, and the New Threat Landscape

Coverage timeline

21 Aug 2026nhimg.orgniteagent.com

Why it matters

MCP tool poisoning and the protocol's name-based trust model let attackers hijack AI agents' tool-calling and exfiltrate data or escalate privileges, an increasingly deployed attack surface defenders must inventory and govern.

An analysis of Model Context Protocol (MCP) security synthesizing SlashID research and related work describes how the protocol's trust model can be abused through tool poisoning, typosquatting, rug pulls, command injection, and sandbox escapes before a model ever reaches external systems. The piece notes that MCP identities are typically approved by name and description while runtime behaviour, scope, and server provenance remain poorly governed, citing statistics that only 18% of MCP deployments scope tool permissions and 53% expose hard-coded credentials, alongside an arXiv STRIDE/DREAD threat model evaluating tool poisoning defenses across seven major MCP clients.