Research · curated 27 Aug 2026
MCP Tool Poisoning: $500 Stolen via a Tool Description
First reported medium.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
MCP tool descriptions are trusted, agent-consumed text that can carry hidden instructions, giving a malicious or compromised MCP server a path to hijack agent actions with almost no dedicated security tooling to detect it.
A red-team write-up by Safiullah Khan demonstrates MCP (Model Context Protocol) tool poisoning, where malicious instructions embedded in a tool's description manipulate an AI agent into taking unauthorized actions — in this lab case, moving $500. The piece is Part 6 of an AI security series and highlights that MCP tool metadata is an attack surface controlled by whoever runs the MCP server.