Opening SecureFlowData Exfiltration via Remote Poisoned MCP Tool
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

MITRE ATLAS mitre-atlas-cs0054

Data Exfiltration via Remote Poisoned MCP Tool

  • Autonomous Agents
  • Tool Integrations & MCP
  • Data Exfiltration
  • Credential & Identity Theft

Researchers at Invariant Labs demonstrated that AI agents configured with remote Model Context Protocol (MCP) Tools can be vulnerable to model poisoning attacks. They show that an MCP Tool can contain malicious prompts in its docstring description, which is ingested into the AI agent's context, modifying its behavior. They demonstrate this attack with a proof-of-concept MCP Tool that instructs the agent to perform additional actions before using the tool. The agent is instructed to read files containing credentials from the victim's machine and store their contents in one of the input variables to the tool. When the tool runs, the victim's credentials are exfiltrated to the poisoned MCP server.

Mapped threat techniques

Source

Updated