MCP Describe Injection: Audit Tool Descriptions Like Code

A practical guide to a real, under-covered MCP attack surface — and a dependency-audit mindset you can apply today. No vendor required for the checklist at the end.

A single install line stamps every tool in an MCP server onto the prompt your model reasons over, and nobody reviews the description. One install becomes a full tool slate — and you never looked at the contents.

The Model Context Protocol is the layer letting agents call tools and read resources across files, databases, email, and internal APIs. That's powerful. It also means a server's metadata — the tool descriptions the model reads at the top of every session — is now part of your attack surface. This post is about one specific, demonstrated attack on that surface: tool poisoning, and how to reduce it with the discipline you already use for dependencies.

1. What tool poisoning is — and why it isn't just indirect prompt injection