Threat scenarios
MCP Tool Poisoning: Threat Scenario & Controls
A malicious or compromised tool can influence the agent before execution.
Illustrative scenario
A tool description or response contains instructions to retrieve secrets and send them elsewhere. The agent treats those instructions as trusted guidance and invokes a downstream export.
This is a generalised threat scenario, not a claim about a named incident or an EndigitalX client.
Controls to examine
Review tool provenance and changes, separate tool output from task authority, restrict identities and destinations, and test tool invocation at the execution boundary.
Testing boundary
Use synthetic data and an authorised test environment. Agree allowed actions and stop conditions before testing; never treat this brief as permission to probe someone else’s systems.
A bounded test scenario
Use a test MCP tool whose description or result contains an instruction to invoke a different, unauthorised action. Keep the environment isolated and the data synthetic.
Observe whether the agent attempts the action and whether the execution boundary denies it. Record tool and policy versions, the supplied content, the attempted call and the decision. An unchanged agent response alone is not proof that access controls held.
This is a generalised test design. It is not a report of a named incident or a complete MCP security assessment.
Start with a clear scope
Tell us which systems, actions and review requirements are in scope. We will discuss the work, responsibilities and deliverables before you commit.