Research · curated 27 Aug 2026

MCP Tool Poisoning: $500 Stolen via a Tool Description

Coverage timeline

23 Aug 2026medium.com

Single-source research — first reported, latest, and curated coincide.

Why it matters

MCP tool descriptions are trusted, agent-consumed text that can carry hidden instructions, giving a malicious or compromised MCP server a path to hijack agent actions with almost no dedicated security tooling to detect it.

A red-team write-up by Safiullah Khan demonstrates MCP (Model Context Protocol) tool poisoning, where malicious instructions embedded in a tool's description manipulate an AI agent into taking unauthorized actions — in this lab case, moving $500. The piece is Part 6 of an AI security series and highlights that MCP tool metadata is an attack surface controlled by whoever runs the MCP server.