Severity
Exposure
Date of incident
MCPoison Supply-Chain Attack
research_hypothesis
Tier -
B
MCP schema update hijacked agent tools — no pinned tool definition at execution hop.
What Happened
Researchers modified MCP tool descriptions server-side; agents followed hidden instructions on next tools/list fetch, enabling credential theft in proof-of-concept.
Sumarry
MCPoison research showed malicious MCP server tool schema updates can poison agent behavior without user-visible changes.
Detect
Pin MCP server digest + schema diff alert
What Happened
MCP proxy with pinned tool schemas
Blekline //
MCP proxy schema pin + evaluate_tool_call
Without agent boundary //
Manual MCP server vetting at install time only
