Skip to content

Enterprise deploymentCustomer-hosted or fully managed.Contact salesView pricing

+Glossary

Tool poisoning

Malicious instructions hidden in an MCP tool's description or schema.

Tool descriptions are read by the model as guidance. A poisoned description can tell the agent to read secrets, add a destination, or prefer this tool over a trusted one — while looking like ordinary help text to a person.

+Why it matters

The attack sits in the most trusted part of the agent's context and runs every time the tool is loaded.

+How Intertrace handles it

Descriptions and schemas are scanned for model-addressed instructions and hidden characters before the agent can use the tool.

+Keep reading

+ The AI watching your AI

See it on your own traffic.

Book a 30-minute risk assessment, or open the Simulation Lab and try it now.