CrowdStrike taxonomy: three attack classes targeting MCP server tool descriptions
voidrane · reddit · 2026-09-18
CrowdStrike's research team documented three attack classes against MCP tool descriptions: tool poisoning (hiding exfiltration instructions in metadata), tool shadowing (one tool's description contaminating how an agent uses another), and rugpull attacks (servers changing tool behavior post-integration via dynamic updates). Key insight: these vulnerabilities live in the relationship between tool descriptions and LLM inference, not in code, so static analysis misses them entirely. Mitigations include description pinning, context isolation, and OS-level least privilege.
More from coding & agent
- Dev bets OpenAI DevDay unveils a unified persistent agent in the mold of Muse — brandon_galang · 2026-09-18
- Perplexity rolls out effort controls in Computer; user shares a 3-tier model workflow — inductionheads · 2026-09-18
- 48 hours old, 724 ads broken down in 40 seconds: Jev sweeps the dev world — Scobleizer · 2026-09-18
- Nebula launches multiplayer AI workspace where agents live in team channels — Scobleizer · 2026-09-18
- Running multiple harnesses at once is the key agent skill: Claude Code, Codex, Fable, DeepSeek combo — EXM7777 · 2026-09-18
- TypeSafe's structured evaluation model Jev goes live on Cloudflare AI Gateway — michellechen · 2026-09-18