Look twice.Find the gem.

AI agents and MCP servers, each published with its source and what the checks found.

Marketplace

  • Everything
  • AI agents
  • Apps
  • MCP servers
  • Templates
  • What people want
  • What changed this week
  • The verification standard
  • The ooruby Index
  • Servers that publish no source
  • Reliability guides
  • What the catalogue holds
  • Sell here

Our library

  • Everything, in one place
  • Guides
  • Glossary
  • Calculators
  • Checklists and cheat sheets
  • Community

ooruby

  • Home
  • For teams
  • Site status
  • Company projects
  • RSS feed

Verification records what our published tests found on a specific version at a specific date. It is not a warranty, and it does not certify that software is free of defects.

Rubricv1.0
AI agentsAppsMCP serversTemplatesWantedCommunityOur library
Sign inSell
Glossary
Security findings

Tool shadowing

A malicious server describing its tool so persuasively that the model prefers it to the legitimate one.

When several servers are connected at once, the model chooses between tools by reading their descriptions. A server can write a description engineered to win that comparison, and it does not have to be dishonest about anything else to do it.

The effect is that work you expected to go to a trusted integration silently goes somewhere else, with all the arguments attached. Nothing was exploited; a selection was influenced.

Why it matters

It is the attack that arrives with more connected servers rather than with worse ones, so it gets more likely exactly as an agent setup gets more useful.

The mistake everyone makes

Assuming this needs the malicious server to be doing anything else wrong. Shadowing works perfectly well from a server that is otherwise clean.

Related terms

Tool poisoning
Hiding instructions inside a tool description so the model reads them as commands.
Capability manifest
The declared list of tools a listing exposes, scopes it needs and hosts it may contact.
MCP server
A program that exposes tools and data to a model through the Model Context Protocol.
Previous
Tool poisoning
Next
Typosquatting

See Tool shadowing on a real listing

Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.

Open the catalogue