Microsoft Incident Response and its Defender security research team have published a detailed advisory warning that attackers can hijack AI agents — including those integrated with Microsoft 365 Copilot, Copilot Studio, and Azure AI Foundry — by embedding malicious instructions in the plain-text descriptions of Model Context Protocol (MCP) tools. The attack, dubbed “tool poisoning,” turns the trust boundary between AI agents and their integrated tooling into a control plane for silent data exfiltration.

MCP tools include plain-text descriptions that tell the AI agent what a tool does and when to use it. Attackers embed hidden instructions — disguised as formatting notes or routine guidance — that manipulate the agent into collecting and transmitting sensitive data to attacker-controlled infrastructure. Because every action the agent takes uses approved tools, existing user permissions, and allowed outbound connections, the exfiltration appears routine and evades standard security controls.

Source

Microsoft Security Blog · The Hacker News · Security Boulevard

Commentary

This advisory matters because it shifts the conversation from “AI can be jailbroken” to “AI agents that act on your behalf can be weaponized through their own supply chain.” The threat is not theoretical — the concept was proven by Invariant Labs in April 2025, a real-world malicious MCP server was caught in September 2025, and OWASP now lists agentic supply chain vulnerabilities in its top-10 for agentic applications.

Microsoft’s key recommendation — “least agency,” limiting an AI agent’s ability to act without human review — is the right framing but runs counter to the entire value proposition of agentic AI. Organizations deploying Copilot, Claude, or any MCP-connected agent need to treat tool descriptions as untrusted input, audit third-party MCP servers the same way they audit npm packages, and implement egress controls that can detect anomalous data flows initiated by AI agents. Microsoft has released a detection tool, but the fundamental design tension remains: agents are only as trustworthy as the tools they consume.

By Allan