A supply-chain attack used to mean a malicious dependency. For agents, there is a second supply chain, and it is made of words: the tool descriptions, extension metadata and protocol defaults that a model reads as instructions while a human sees nothing.
Tool poisoning: the description is the payload
The Model Context Protocol connects an agent to servers that expose tools. Each tool carries a name, a schema and a description. The description is help text, except that a model reads it as part of its context, and no human ever does. OWASP’s MCP Top 10 lists tool poisoning as a distinct category, and the Cloud Security Alliance called the description field “an unsanitized attack surface”: a malicious or compromised server can embed instructions in what appears to be documentation, and the agent will follow them.
This is not speculation about the future. Microsoft has published guidance on defending against tool poisoning, and multiple high-severity findings across developer IDEs were disclosed between mid-2025 and mid-2026.
The protocol itself, “by design”
The deeper finding is the one that is hardest to patch, because the vendor declined to patch it. In the MCP STDIO transport, passing a malicious command can return an error, and the command still runs. The “Mother of All AI Supply Chains” case study documents this as reachable across hundreds of projects, thousands of exposed servers and on the order of two hundred thousand instances. Anthropic’s position was that this is expected behavior, not a vulnerability.
Whatever one thinks of that answer, it clarifies the boundary: the protocol layer will not be where this gets fixed. It has to be fixed at the point where a tool’s definition is allowed to reach an agent, which means pinning and verifying the definitions an agent is actually allowed to call.
The extension angle
Two incidents show how the same idea travels through an IDE.
Amazon Q. An attacker injected a prompt into the official AWS extension telling Amazon Q to delete filesystems and wipe S3 buckets. It worked, and across more than a million installs, the only thing that prevented mass destruction was a syntax error in the injected command.
Cline. Prompt injection on Cline’s issue-triage bot led to stolen npm tokens and a published malicious package, compromising roughly four thousand developers in about eight hours.
Neither required a novel exploit. Both required only that untrusted text reach an agent that had the credentials to act.
Why pinning is the control, not scanning
The common thread is that these agents trusted content they should have treated as data: a tool description, an extension message, a triage comment. The structural defense is the same one that closes grant rug-pulls: pin every tool definition before it is forwarded, and hold the agent to an authority it was actually granted. A hash of the tool’s name, description, schema and server identity is a membership test: it either matches what a person approved, or the grant is void. No classifier is asked to judge whether the words are “malicious,” because the question is not about the words at all.
Sources accessed 2026-09-20. MCP tool poisoning: CSA research note and Microsoft (PRIMARY). The STDIO-RCE, Amazon Q and Cline cases are community-documented case studies in awesome-agent-failures (SECONDARY).