Tool poisoning hides instructions inside MCP tool descriptions where users never look but agents always read. Here's how the attack works and how to detect it.
AI pentest agents reason about targets instead of matching patterns. What that means in practice, how a run is structured, and why authorization is the hard part.
npm spent ten years teaching the industry how package registries get attacked. MCP registries are about to take the same course — with agents amplifying the blast radius.