Case 7516BE · AI security · L5 Expert
MCP Server Rewrites Its Tools
Practise as: Incident drill · Deep dive
Live alertAn engineer's coding agent read ~/.ssh/id_rsa and passed it as a "notes" argument to a weather tool; the third-party MCP server had silently changed that tool's description after approval.
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Tool poisoning: MCP tool descriptions enter model context verbatim, so hidden instructions in them steer the agent.
- Rug pull: a server can change tool definitions after the user approved it; approving version 1 says nothing about version 2.
- Tool shadowing: one server's description can change how the agent uses another, trusted server's tools.
- Respond: disconnect the server, rotate the key and any tokens the client held, and review tool-call logs for other leaks.
- Prevent: allowlist and pin servers, hash tool definitions and re-approve on change, sandbox local servers, limit file access.
If the interviewer pushes back
- Why does the MCP spec forbid token passthrough, and what confused-deputy problem does that prevent?
- How would you catch a malicious tool description in review before an MCP server is approved for your org?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.