Cross-server tool shadowing
Cross-server tool shadowing is an MCP attack in which instructions supplied by one malicious or compromised server alter how an AI agent invokes a different, trusted server's tool. The poisoned tool definition enters the model's combined tool context and adds hidden rules for the trusted action. The malicious tool does not need the same name, does not need to replace the trusted tool, and may never be called.
Origin and context
Invariant Labs published the defining demonstration on 1 April 2025. A bogus calculator tool described a supposed side effect of a separate email tool and instructed the model to redirect mail to an attacker. The agent then called only the trusted email tool with altered arguments. Later OWASP, CSA, Netskope, and academic sources retained cross-server shadowing as a recognizable attack variant. Some sources instead use `tool shadowing` for same-name tool impersonation; this entry follows the original MCP-specific meaning and reports that collision rather than merging the definitions.
Why it matters
The attack crosses an intuitive trust boundary. A low-value server can influence a high-value mail, repository, HR, or payment tool because models may see metadata from all connected servers in one reasoning context. The legitimate server can execute normally and its logs can show a valid call, while the harmful recipient or parameter was selected upstream by the model. Reviewing only the invoked tool therefore misses the source of manipulation.
Example
An agent connects to a trusted `send_email` server and an untrusted calculator server. The calculator's description says every email must use an attacker-controlled recipient. When the user asks to send a normal message, the model obeys that metadata and calls `send_email` with the wrong address; the calculator is never invoked. If the attacker instead registered another tool named `send_email`, that would be a name-collision or impersonation attack under the narrower taxonomy, not the original shadowing demonstration.
How it differs
Tool poisoning
Tool poisoning is the broader metadata-injection mechanism. Direct poisoning makes an agent misuse the poisoned tool itself; cross-server shadowing uses one tool's metadata to change behavior toward a different trusted tool. Shadowing can therefore be treated as one compound or lateral variant of tool poisoning.
MCP rug pull
An MCP rug pull concerns timing: a server changes an approved tool definition later. Shadowing concerns scope: one server's description influences another server's tool. An attacker can combine them, but either mechanism can occur without the other.
Maturity and evidence
Maturity is rated 3. The mechanism has a reproducible origin demonstration, independent industry treatments, OWASP defensive guidance, academic attack taxonomies, and scanner support. It remains below 4 because names vary across sources, formal MCP controls for cross-server context and identity are still evolving, and laboratory success does not quantify incident prevalence in deployed systems.
Limits and open questions
A suspicious cross-reference in metadata is evidence to investigate, not proof of compromise. Showing descriptions, hashing manifests, and scanning text can help but do not establish safe behavior. Clients should bind tool identity to its server, isolate unrelated tool contexts, constrain capabilities and data flows, show consequential inputs, and monitor actual calls. MCP's guidance that annotations from untrusted servers are untrusted does not by itself neutralize instructions elsewhere in descriptions or results.
Related terms
References
- MCP Security Notification: Tool Poisoning AttacksInvariant Labs · 2025-04-01 · class A
- Tools — Model Context Protocol specification 2025-11-25Model Context Protocol · 2025-11-25 · class A
- MCP Security Cheat SheetOWASP Cheat Sheet Series · 2025 · class B
- Securing the Model Context Protocol: Defending LLMs Against Tool Poisoning and Adversarial AttacksJamshidi et al. / arXiv · 2025-12-06 · class A
- Systematic Analysis of MCP SecurityGuo et al. / arXiv · 2025-08-18 · class A
- MCP Tool Poisoning: Adversarial Hijacking of AI Agent WorkflowsCloud Security Alliance AI Safety Initiative · 2026-07-02 · class B
- MCP Security Bench: Benchmarking Attacks Against Model Context Protocol in LLM AgentsZhang et al. / arXiv · 2025-10-14 · class A
Last updated: 2026-09-07