Analysis · curated 21 Aug 2026
MCP's Broken Trust Model: Tool Poisoning, Rug Pulls, and the New Threat Landscape
First reported · updated · 3 reports nhimg.org
Coverage timeline
Why it matters
MCP tool poisoning and the protocol's name-based trust model let attackers hijack AI agents' tool-calling and exfiltrate data or escalate privileges, an increasingly deployed attack surface defenders must inventory and govern.
An analysis of Model Context Protocol (MCP) security synthesizing SlashID research and related work describes how the protocol's trust model can be abused through tool poisoning, typosquatting, rug pulls, command injection, and sandbox escapes before a model ever reaches external systems. The piece notes that MCP identities are typically approved by name and description while runtime behaviour, scope, and server provenance remain poorly governed, citing statistics that only 18% of MCP deployments scope tool permissions and 53% expose hard-coded credentials, alongside an arXiv STRIDE/DREAD threat model evaluating tool poisoning defenses across seven major MCP clients.