Tool Poisoning on MCP Servers: The Attack Vector Nobody's Patching
CrowdStrike published a taxonomy of attacks on MCP servers: tool description poisoning, cross-tool contamination, and description substitution after integration. Traditional static analysis does not detect such threats, and attacks are already being recorded in real incidents involving Claude Code and Cursor.
- Three attack classes: tool poisoning, tool shadowing, and rugpull after integration
- Hidden instructions in tool descriptions evade static code analysis
- GitSpawn allows code execution in Claude Code and Cursor via tool context
- CrowdStrike's Falcon Guardian is the first tool to trace prompts through calls
Read next
Security