AI ART ECO SOC RO Rohit Anand · Signal & Structure Tool Poisoning: The Supply Chain Attack Nobody’s Watching For How a compromised MCP server or malicious tool manifest can hijack an agent’s workflow — the npm left-pad incident for the agent era.
AI GEN HUM SA Saif Ullah Control Plane Governance for MCP Tool Integrations: The Registry Pattern When your agent trusts what it’s told, authority belongs to the upstream provider.
AI YA Yaniv Ai Tool Poisoning: Hidden Instructions In Tool Metadata TL;DR: Attackers can embed hidden instructions in tool descriptions consumed by ai agents (via mcp), causing agents to source local secrets…