A tool server is reviewed once, when you connect to it. The text it returns days later goes straight into the model's context with no equivalent check, so an instruction hidden in a tool result is read as though you had written it.
What people are trying
- MCP Tool Poisoning · OWASP Foundation · read 09/19/2026
Fully detecting injected instructions in free-text responses is an open problem, but schema validation catches the obvious cases.
Where it bites: Model Context Protocol