Glossary · term
Tool poisoning
An attack on the Model Context Protocol that hides malicious instructions in a tool's description: they are invisible to the user but read by the model. The model executes the hidden commands — for example, reading SSH keys — during a seemingly harmless operation. Described by Invariant Labs in April 2025.
AgentsIV 2025Wave 2 · 2024Maturity: 1/5
Maturity rationale
Tool poisoning — early MCP security term
References
Author: Invariant Labs