Microsoft warns poisoned MCP tool descriptions can leak agent data
Attackers can hide malicious instructions inside legitimate-looking tool metadata, tricking AI agents into exfiltrating data without user awareness.

- ▸Microsoft has warned that poisoned MCP (Model Context Protocol) tool descriptions can trick AI agents
- ▸Malicious instructions can be hidden inside otherwise legitimate-looking tool metadata
- ▸Affected agents can be manipulated into leaking data without the user noticing
- ▸The warning follows an April disclosure of a separate MCP design vulnerability enabling remote code execution
The metadata layer nobody was watching
Tool descriptions were designed to help an agent decide what a tool does — not to be treated as untrusted input. Microsoft's warning highlights a blind spot: metadata meant purely for the model to read can itself become an injection vector.
Source: The Hacker News


