Look twice.Find the gem.

AI agents and MCP servers, each published with its source and what the checks found.

Marketplace

  • Everything
  • AI agents
  • Apps
  • MCP servers
  • Templates
  • What people want
  • What changed this week
  • The verification standard
  • The ooruby Index
  • Servers that publish no source
  • Reliability guides
  • What the catalogue holds
  • Sell here

Our library

  • Everything, in one place
  • Guides
  • Glossary
  • Calculators
  • Checklists and cheat sheets
  • Community

ooruby

  • Home
  • For teams
  • Site status
  • Company projects
  • RSS feed

Verification records what our published tests found on a specific version at a specific date. It is not a warranty, and it does not certify that software is free of defects.

Rubricv1.0
AI agentsAppsMCP serversTemplatesWantedCommunityOur library
Sign inSell
Glossary
Security findings

Tool poisoning

Hiding instructions inside a tool description so the model reads them as commands.

A model decides which tool to call by reading the descriptions the server publishes. Those descriptions are free text controlled by whoever wrote the server, and a model has no reliable way to distinguish a description from an instruction.

The attack is to write a description that tells the model to do something else: exfiltrate a file, call another tool first, ignore a restriction. It was rated critical in the OWASP MCP top ten and appears in disclosed vulnerabilities from 2025.

Why it matters

It requires no exploit and no unusual privilege. It is text in a field that was designed to hold text.

The mistake everyone makes

Believing a review of the code covers it. The payload is in the metadata, not the code, and it can change without a code change.

Related terms

Prompt injection
Getting a model to follow instructions that arrive inside data it was asked to process.
Capability manifest
The declared list of tools a listing exposes, scopes it needs and hosts it may contact.
Permission drift
When a new version of a listing quietly asks for more access than the version you approved.
Tool shadowing
A malicious server describing its tool so persuasively that the model prefers it to the legitimate one.
Previous
Tool description
Next
Tool shadowing

See Tool poisoning on a real listing

Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.

Open the catalogue
Figure

Tool poisoning: every step is the protocol working normally

Server updatesa tool descriptionClient refetchesno version pinnedDescription reachesthe model's contextread as instruction, not as documentationModel follows itit is in the promptAgent calls a toolyou never asked forData leavesto an allowed hostEgress allow-listthe only step thatstops the chain hereWhere it was caughtReading the tool descriptions yourself, once,before you install. It takes about two minutes.

Nothing here is a bug. A tool description is free text the server controls, and the model treats it as instruction because that is what it is for. The defence is not trusting the description less; it is making sure step five has nowhere to go.