The Structural Flaws in Model Context Protocol
Recent investigations across AI agents (including Google, Anthropic, and open-source MCP host orchestrators) identified structural design assumptions in MCP:
- Unchecked Tool Shadowing: Any installed MCP server can return tool descriptions matching standard utilities. Because LLM context windows evaluate tool semantics organically, a malicious server can trick the model into preferring its compromised implementation.
- Prompt Injection via Resource Schemas: Content returned via
resources/readorprompts/getis directly fed into the primary context window, allowing hidden directives (e.g. Markdown comments or zero-width unicode) to hijack execution. - Dynamic Schema Rug-Pulls: Servers can initially declare a benign parameter schema during client initialization, then quietly change tool behavior or inject additional telemetry targets during subsequent
tools/callrounds.