Connect Clawsmith to your coding agent. Ship products like crazy.Unlimited usage during betaGet API Key โ†’
โ† Back to dashboard
clawsmith.com/signal/mcp-tool-poisoning-prompt-injection
โš  IssueUnderservedToolLive

MCP Tool Poisoning: Attackers Hide Malicious Instructions in Tool Descriptions to Exfiltrate SSH Keys and Private Repos

Malicious MCP servers embed hidden instructions in tool description fields โ€” text that lands in the LLM context window and gets treated as trusted input. Demonstrated real attacks: GitHub MCP poisoning exfiltrated private repo data via a malicious public issue; WhatsApp rug-pull redirected chat histories to attacker server; Cursor agent processed poisoned support tickets and leaked tokens. OWASP named it #3 in MCP Top 10 2025. CVE-2025-54136 assigned. 5.5% of 1,899 public MCP servers found poisoned in scan.

Score Breakdown

HN
913
Issues
221

Gap Assessment

UnderservedExisting solutions leave gaps

mcp-scan by Invariant Labs is the main static analyzer. No universal runtime defense standard. mcp-safe-fetch, MCPShield, AIP (Agent Identity Protocol) all early-stage.

Frequently Asked Questions