Microsoft advisory: poisoned MCP tool descriptions can silently redirect agents to exfiltrate data
2026-microsoft-mcp-tool-description-poisoning · 2026-06-30
Microsoft Incident Response and Microsoft Defender researchers warned that a poisoned Model Context Protocol tool description can embed hidden instructions an agent follows, using the user's own permissions to collect and exfiltrate business data. Because MCP can pick up description changes dynamically, a poisoned version can take effect without a new approval step.
System
- Framework
- Microsoft 365 Copilot / Copilot Studio / Azure AI Foundry / custom MCP servers
- Tools
- mcp, copilot
- Vendor
- Microsoft
- Autonomy
- supervised-autonomous
Classification
- Primary class
- prompt-injection
- Chain
- prompt-injection/tool-metadata → data-exfiltration/via-tool
- Attack vector
- tool-metadata
- Causation
- entity: human · intentionality: intentional · timing: post-deployment
Trigger
A tool connected via MCP carries a plain-text description that tells the agent what it does. An attacker poisons that description with hidden instructions; because MCP can pick up description changes dynamically, the poisoned version becomes active without a new approval step in default setups. When a user makes a normal request, the agent follows the hidden instruction and copies data to an attacker-controlled tool while returning a normal-looking answer.
Root cause
AI agents treat third-party MCP tool descriptions as trusted instructions. This is a trust-boundary problem, not a bug in the assistant: descriptions from external tools enter the model context with the standing of instructions, and dynamic description updates bypass the initial approval.
Contributing factors
- MCP tool descriptions can change after approval and take effect without re-review.
- Tool descriptions are consumed as instructions rather than as untrusted data.
- Actions run with the requesting user's permissions, so exfiltration looks routine.
Detection
Documented by Microsoft Incident Response and Microsoft Defender researchers in a public advisory; reported by multiple security outlets.
Recovery
Microsoft published guidance for teams approving agents that connect to business systems, emphasising treating tool descriptions as untrusted and re-reviewing on change. No specific in-the-wild exploitation was reported in the advisory.
Prevention
Treat MCP tool metadata as untrusted input; pin and re-review tool descriptions on change; require approval before cross-tool data movement; constrain the destinations tools may send data to; isolate untrusted tools from sensitive ones.
Blast radius
- Data
- Business data reachable by an enterprise agent (e.g. supplier invoices in the advisory's example) could be collected under the user's permissions and copied to an attacker-controlled server. confidential
- User harm
- A vendor advisory describing an attack class; no specific in-the-wild exploitation was reported. none-reported
- Scope
- enterprise agents connecting business systems via MCP
- Reversibility
- irreversible
References
- OWASP LLM
- LLM01 LLM02
- MITRE ATLAS
- AML.T0024 AML.T0051
- Tags
- mcp tool-poisoning copilot vendor-advisory
Sources
Cite this incident
Permalink: https://swarmproof.github.io/agent-postmortems/2026-microsoft-mcp-tool-description-poisoning/
@misc{2026-microsoft-mcp-tool-description-poisoning,
title = {Microsoft advisory: poisoned MCP tool descriptions can silently redirect agents to exfiltrate data},
year = {2026},
howpublished = {agent-postmortems},
url = {https://swarmproof.github.io/agent-postmortems/2026-microsoft-mcp-tool-description-poisoning/}
}