Severity

critical

Exposure

5/5

Date of incident

November 1, 2024
MCPoison Supply-Chain Attack

research_hypothesis

Tier -

B

MCP schema update hijacked agent tools — no pinned tool definition at execution hop.
What Happened

Researchers modified MCP tool descriptions server-side; agents followed hidden instructions on next tools/list fetch, enabling credential theft in proof-of-concept.

Sumarry

MCPoison research showed malicious MCP server tool schema updates can poison agent behavior without user-visible changes.

Detect

Pin MCP server digest + schema diff alert

What Happened

MCP proxy with pinned tool schemas

Blekline //

MCP proxy schema pin + evaluate_tool_call

Without agent boundary //

Manual MCP server vetting at install time only

Financial services AI security use case

Looking to integrate AI company-wide?