MCP Server Tool Descriptions Can Change Silently, Putting AI Agents at Risk

AI coding agents like Claude Code, Cursor, and Codex read tool names, descriptions, and schemas from MCP servers on every session, effectively treating that content as part of their instructions. Because these descriptions can be updated by server publishers at any time, a malicious or compromised update can inject new commands into an agent without triggering any re-approval alert. A proof-of-concept example showed a tool description quietly modified to instruct the agent to read and transmit AWS credentials, while the tool still appeared approved in the client. A new open-source tool called mcpgawk addresses this by fingerprinting each tool at approval time and blocking any call where the description or schema has since changed. The tool runs locally, requires human review before unblocking a changed tool, and supports major agent platforms including Cursor, Codex, Windsurf, and Gemini CLI.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.



Discussion (0)
Log in to join the discussion and vote.
Log in