Definition

Malicious instructions smuggled via tool descriptions, retrieved content or untrusted annotations. MCP warns that tool descriptions should be treated as untrusted unless from a trusted server.

Used in this bundle

Appears in: failure-taxonomy, mcp.

Related terms

least privilege.