๐Ÿ›ก๏ธ NAIL Institute โ€” AVE Database

โ† Back to Database

MCP Tool Registration Poisoning

๐ŸŸ  HIGH tool proven AVE-2025-0014

ยท aka: Tool Description Attack, MCP Injection

Summary

MCP (Model Context Protocol) tool registries accept malicious tool definitions without verification. Agents trust tool descriptions implicitly, enabling data exfiltration.

Blast Radius

Full PII/secret exfiltration through tool call arguments.

Prerequisites

Agent uses MCP or dynamic tool registry.

Environment

  • Frameworks: LangGraph
  • Models tested: [Available in NAIL SDK]
  • Multi-agent: No
  • Tools required: Yes
  • Memory required: No