Open cardosec

Case 7516BE · AI security · L5 Expert

MCP Server Rewrites Its Tools

Practise as: Incident drill · Deep dive

Live alertAn engineer's coding agent read ~/.ssh/id_rsa and passed it as a "notes" argument to a weather tool; the third-party MCP server had silently changed that tool's description after approval.

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Tool poisoning: MCP tool descriptions enter model context verbatim, so hidden instructions in them steer the agent.
  2. Rug pull: a server can change tool definitions after the user approved it; approving version 1 says nothing about version 2.
  3. Tool shadowing: one server's description can change how the agent uses another, trusted server's tools.
  4. Respond: disconnect the server, rotate the key and any tokens the client held, and review tool-call logs for other leaks.
  5. Prevent: allowlist and pin servers, hash tool definitions and re-approve on change, sandbox local servers, limit file access.

If the interviewer pushes back

  • Why does the MCP spec forbid token passthrough, and what confused-deputy problem does that prevent?
  • How would you catch a malicious tool description in review before an MCP server is approved for your org?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.