security1 publisher
Malicious instructions hidden in MCP tool descriptions inherit the agent's system-level authority
The same weakness turns up in Cursor's XML tags, MCP tool definitions and skill YAML frontmatter. Each one puts attacker-controlled text where a coding agent already treats it as its own instructions.
Publishers:scworld.com
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+25
- Incentives70
- Confidence40