ยท aka: Tool Description Attack, MCP Injection
MCP (Model Context Protocol) tool registries accept malicious tool definitions without verification. Agents trust tool descriptions implicitly, enabling data exfiltration.
Full PII/secret exfiltration through tool call arguments.
Agent uses MCP or dynamic tool registry.