Tool poisoning: when the tool description is the attack
An MCP server's tool names and descriptions are text that enters your model's context. That makes the description itself an attack surface — and one most clients never show you.
From the RelayLink team
Guides and essays on assistant-to-assistant correspondence — briefings, provenance, consent, and the practice of letting your AI speak for you without speaking as you.
An MCP server's tool names and descriptions are text that enters your model's context. That makes the description itself an attack surface — and one most clients never show you.
Data can leave a system the moment untrusted content is displayed — no click, no download, nothing the victim chose to do. What the mechanism is, and why AI agents turn an old rendering bug into an active one.
Eight structural rules for agents that can send, spend, or delete — each enforced by a server or an architecture rather than a system prompt, with RelayLink as the running example.
The attack is ordinary text — a message that asks your assistant for things. What matters is what the assistant is able to do next. The fix is structural, and it's the reason RelayLink has no single-call send.