A practical catalogue of how Model Context Protocol servers can be used to attack the person running them, why the client UI does not show any of it, and what to do about each case.
This document is maintained alongside toolpoison, a scanner that detects most of what is described here. It is written to be useful on its own.
Contents
Why MCP has this problem
Tool poisoning






