Definition
What is Tool Poisoning?
Last updated
An attack in which malicious instructions are embedded in an MCP tool's description or metadata so an agent treats them as authoritative context and acts on them.
Agents read tool descriptions into the same context window they use for user prompts and retrieved documents. Anything in those descriptions is trusted by default. Attackers exploit this by hiding instructions, swapping descriptions after install, or registering near-duplicate tools, turning the tool registry into a persistent compromise channel. The MCPTox benchmark documented a 72.8% attack success rate across 20 production agents in 2025.
All terms
View full glossary Agent Drift AI Agent Agent Reliability AI Hallucination AI Second Brain Chunking Context as a Service Context Compression Context Bloat Context Container Context Engineering Context Offloading Context Drift Context Portability Context Pruning Context Poisoning Context Rot Context Window Epistemic Provenance Fine-Tuning Knowledge Graph MCP Resources MCP Server MCP (Model Context Protocol) Multi-Agent System Prompt Caching Prompt Engineering Semantic Search RAG (Retrieval-Augmented Generation) Structured Context Tool Poisoning Wire
Put context into practice
Create your first context container and connect it to your AI tools in minutes.
Create Your First Container