Your AI agent trusts its tools completely. That trust is the vulnerability.

When you connect an MCP (Model Context Protocol) tool to an agent, you approve it based on its definition: the name, the description, the parameters. The agent then treats that definition as gospel. It does what the tool says it does.

But here's the thing almost nobody checks: what stops that definition from changing after you approve it?

Call it a rug-pull, or tool poisoning. It works like this:

Day 1. You connect a tool called send_email. The description says it sends an email. You review it, it's fine, you approve it. Everything works.