Glossary · term

Tool poisoning

An attack on the Model Context Protocol that hides malicious instructions in a tool's description: they are invisible to the user but read by the model. The model executes the hidden commands — for example, reading SSH keys — during a seemingly harmless operation. Described by Invariant Labs in April 2025.

AgentsIV 2025Wave 2 · 2024Maturity: 1/5

Maturity rationale

Tool poisoning — early MCP security term

References

Author: Invariant Labs