May 2026Unreviewed
When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents
Shi Liu, Xuehai Tang, Xikang Yang, Liang Lin, Biyu Zhou, Wenjie Xiao, Wantao Liu
Abstract
The rise of tool-using Large Language Model (LLM) agents, standardized by protocols like the Model Context Protocol (MCP), has unlocked unprecedented autonomous execution capabilities for LLM Agents by integrating external open-domain knowledge and tools. However, this interoperability introduces a covert attack surface targeting the agent's cognitive planning layer. This paper systematically investigates Tool Description Poisoning (TDP), a novel semantic attack. In TDP, malicious instructions a
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM04Data and Model Poisoning
MITRE ATLAS
- AML.T0020Poison Training Data
Suggested from the entry's categories.
Cite
@misc{liu2026whenb,
title = {{When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents}},
author = {Shi Liu and Xuehai Tang and Xikang Yang and Liang Lin and Biyu Zhou and Wenjie Xiao and Wantao Liu},
year = {2026},
month = may,
eprint = {2605.24069},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2605.24069}
}