Tool poisoning
Hiding instructions inside a tool description so the model reads them as commands.
A model decides which tool to call by reading the descriptions the server publishes. Those descriptions are free text controlled by whoever wrote the server, and a model has no reliable way to distinguish a description from an instruction.
The attack is to write a description that tells the model to do something else: exfiltrate a file, call another tool first, ignore a restriction. It was rated critical in the OWASP MCP top ten and appears in disclosed vulnerabilities from 2025.
It requires no exploit and no unusual privilege. It is text in a field that was designed to hold text.
Believing a review of the code covers it. The payload is in the metadata, not the code, and it can change without a code change.
Related terms
See Tool poisoning on a real listing
Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.
Open the catalogue