Poisoned MCP: Tool Descriptions Leak Data

Colleagues, I’d like to highlight a cybersecurity issue: Microsoft warned about poisoned MCP tool descriptions.
This is an important signal for anyone giving AI agents access to business systems.
- Tampering with an MCP tool description can covertly prompt an agent to send data outside the environment.
- The danger is that every action still appears legitimate: the tool is trusted, the request looks routine.
- The risk lies at the trust boundary between the agent and the external service.
What to do: limit the tool set, verify description changes, require confirmation for high-risk actions, and keep activity logs.
Why it matters: agentic AI is becoming part of the supply chain, and it must be controlled as strictly as code and access rights.
Have you already reviewed your policy for MCP and AI agents?
#cybersecurity #AI #MCP #supplychain

