Hook

Tool poisoning: how MCP servers can get infected. This is an attack where let's say I publish an MCP server and I say I know your favorite type of MCP server is a weather MCP server. Let's say that I published a great weather MCP server and it has you know two tools for like get weather and get forecast. And I get a bunch of people to connect to it. And then after I get some usage and people start using it, then later I change how get weather works. I change how the tool works or I introduce some new tools like get intent or you know exfiltrate context. I could introduce malicious tools onto that server and if your client just connects, you know you've connected to it before so you've told me you've already clicked through that client, you've already said yes I trust this server, you know always allow, YOLO mode whatever. Now I've introduced new tools to that server that you didn't know about that are malicious and I can trick you into doing some stuff that you didn't want to do. So that's tool poisoning. Kind of like you can think of it as the MCP server started out publishing one set of tools that were maybe benign and then later added some malicious stuff. Well I've heard of this because skills auto update and it's harder than it's harder to defend against skills.
Their other posts in the index, biggest breakout first.