MCP server security in 2026: tool poisoning, rug pulls, token passthrough — a practical checklist
Short answer
The main MCP risks are tool poisoning (hidden instructions in tool descriptions that the model follows but the user never sees), rug pulls (a server changing its tool descriptions after you approved it), cross-server shadowing, token passthrough and local server compromise. Invariant Labs demonstrated tool poisoning on April 1, 2025, exfiltrating SSH keys and MCP configuration files through Cursor. The MCP specification’s security best practices (version 2026-07-28) state that MCP servers MUST NOT accept tokens not explicitly issued for them, and that clients offering one-click local server setup MUST show the exact command and obtain consent before running it. Pin server versions, review tool descriptions, minimize scopes and never pass tokens through.
Last updated · Sekrd Research
- Tool poisoning disclosed by Invariant Labs on April 1, 2025; demonstrated exfiltration of
~/.ssh/id_rsaand~/.cursor/mcp.jsonin Cursor. - MCP spec, security best practices (2026-07-28): servers MUST NOT accept tokens that were not explicitly issued for them.
- Clients that support one-click local MCP server configuration MUST show the exact command, untruncated, and obtain consent before executing it.
- Lovable’s publish-time Quick Scan flags unauthenticated MCP servers.
The attacks, briefly
Tool poisoning
Models read the full description of every tool a server exposes; users usually see a short name. Invariant Labs showed that instructions hidden in a description — for example inside an <IMPORTANT> block of an innocent “add two numbers” tool — can make the model read local files and send their contents out through the tool’s own parameters, while telling the user it just did arithmetic.
Rug pulls
A server you approved can change its tool descriptions later. Approval at install time says nothing about what the server says tomorrow — the same problem as a compromised package update.
Shadowing
A malicious server can describe behavior that changes how the model uses other, trusted servers — Invariant’s example redirected emails sent through a legitimate email tool.
Token passthrough
An MCP server that accepts a token issued for some other service and forwards it downstream becomes a confused deputy. The specification forbids it: servers MUST NOT accept tokens not explicitly issued for them, which in practice means validating the token’s audience.
Local server compromise
Local MCP servers are programs running with your user’s privileges. The specification gives examples of malicious startup commands that exfiltrate SSH keys or delete files, and requires clients to show the exact command and get consent before running a newly configured local server.
Checklist for using MCP servers
- Install servers only from sources you trust; pin versions and verify checksums.
- Read the full tool descriptions, not the UI summary. Look for instructions addressed to the model.
- Re-review when a server updates — treat description changes like code changes.
- Do not connect high-privilege servers (email, file system, production databases) in the same session as untrusted ones.
- Grant the smallest scopes the task needs; avoid wildcard scopes such as
files:*oradmin:*.
Checklist for building MCP servers
- Require authentication on remote servers; never expose an unauthenticated server to the internet.
- Validate token audience and never forward client tokens to downstream APIs.
- Keep tool descriptions short, factual and free of instructions.
- Guard against SSRF if your server fetches URLs supplied by clients or other servers.
- Scope file-system access to an explicit directory, never the home folder.
- Log tool invocations with arguments so misuse is visible.
Frequently asked questions
What is MCP tool poisoning?
An attack where a Model Context Protocol server hides instructions inside a tool description. The AI model reads and follows them while the user only sees a simplified tool name. Invariant Labs demonstrated it on April 1, 2025, exfiltrating SSH keys and MCP config files through Cursor.
What is an MCP rug pull?
A server changing its tool descriptions or behavior after the user approved it, turning a previously trusted tool malicious. Pinning server versions and re-reviewing updates mitigates it.
What does the MCP specification require for security?
Among other requirements in the 2026-07-28 security best practices: servers MUST NOT accept tokens not explicitly issued for them, and clients offering one-click local server configuration MUST display the exact command and obtain user consent before executing it.
Sources
Don't ship until you're sekrd
Run a free scan to find the vulnerabilities your AI missed.
Scan Your App Free