agent-postmortems a structured database of real AI-agent failures

← all incidents

hazard high confidence: corroborated status: factual

Microsoft advisory: poisoned MCP tool descriptions can silently redirect agents to exfiltrate data

2026-microsoft-mcp-tool-description-poisoning · 2026-06-30

Microsoft Incident Response and Microsoft Defender researchers warned that a poisoned Model Context Protocol tool description can embed hidden instructions an agent follows, using the user's own permissions to collect and exfiltrate business data. Because MCP can pick up description changes dynamically, a poisoned version can take effect without a new approval step.

System

Framework
Microsoft 365 Copilot / Copilot Studio / Azure AI Foundry / custom MCP servers
Tools
mcp, copilot
Vendor
Microsoft
Autonomy
supervised-autonomous

Classification

Primary class
prompt-injection
Chain
prompt-injection/tool-metadata → data-exfiltration/via-tool
Attack vector
tool-metadata
Causation
entity: human · intentionality: intentional · timing: post-deployment

Trigger

A tool connected via MCP carries a plain-text description that tells the agent what it does. An attacker poisons that description with hidden instructions; because MCP can pick up description changes dynamically, the poisoned version becomes active without a new approval step in default setups. When a user makes a normal request, the agent follows the hidden instruction and copies data to an attacker-controlled tool while returning a normal-looking answer.

Root cause

AI agents treat third-party MCP tool descriptions as trusted instructions. This is a trust-boundary problem, not a bug in the assistant: descriptions from external tools enter the model context with the standing of instructions, and dynamic description updates bypass the initial approval.

Contributing factors

  • MCP tool descriptions can change after approval and take effect without re-review.
  • Tool descriptions are consumed as instructions rather than as untrusted data.
  • Actions run with the requesting user's permissions, so exfiltration looks routine.

Detection

Documented by Microsoft Incident Response and Microsoft Defender researchers in a public advisory; reported by multiple security outlets.

Recovery

Microsoft published guidance for teams approving agents that connect to business systems, emphasising treating tool descriptions as untrusted and re-reviewing on change. No specific in-the-wild exploitation was reported in the advisory.

Prevention

Treat MCP tool metadata as untrusted input; pin and re-review tool descriptions on change; require approval before cross-tool data movement; constrain the destinations tools may send data to; isolate untrusted tools from sensitive ones.

Blast radius

Data
Business data reachable by an enterprise agent (e.g. supplier invoices in the advisory's example) could be collected under the user's permissions and copied to an attacker-controlled server. confidential
User harm
A vendor advisory describing an attack class; no specific in-the-wild exploitation was reported. none-reported
Scope
enterprise agents connecting business systems via MCP
Reversibility
irreversible

References

OWASP LLM
LLM01 LLM02
MITRE ATLAS
AML.T0024 AML.T0051
Tags
mcp tool-poisoning copilot vendor-advisory

Sources

Cite this incident

@misc{2026-microsoft-mcp-tool-description-poisoning,
  title = {Microsoft advisory: poisoned MCP tool descriptions can silently redirect agents to exfiltrate data},
  year = {2026},
  howpublished = {agent-postmortems},
  url = {https://swarmproof.github.io/agent-postmortems/2026-microsoft-mcp-tool-description-poisoning/}
}