MCP tool descriptions are text. When your agent calls tools/list, the server returns JSON with a description field for each tool. That text goes directly into the LLM's context window. The model reads it, reasons about it, and follows instructions it finds there.
A malicious MCP server puts instructions in descriptions. Your agent follows them....
🛡️ VERIFIED CYBER INTELLIGENCE ID: #3300298
🔧 Your MCP server's tool descriptions are an attack surface
Verwandte Security Videos · KI-empfohlen via Levenshtein-Match
🎯 37% Match
📆 24.06.2025 um 18:00 Uhr
▶ Abspielen
← Horizontal scrollen für mehr Empfehlungen → · Klick auf ein Video zum Abspielen im Hauptplayer