What is MCP tool poisoning?
Hiding malicious instructions inside an MCP server's tool descriptions or metadata — text the user never sees but the model reads and follows, such as an instruction to attach an environment variable to an outbound request. OWASP catalogs it as a distinct attack class.
