Skip to content
Search
paperMay 2026Unreviewed

When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents

Shi Liu, Xuehai Tang, Xikang Yang, Liang Lin, Biyu Zhou, Wenjie Xiao, Wantao Liu

Abstract

The rise of tool-using Large Language Model (LLM) agents, standardized by protocols like the Model Context Protocol (MCP), has unlocked unprecedented autonomous execution capabilities for LLM Agents by integrating external open-domain knowledge and tools. However, this interoperability introduces a covert attack surface targeting the agent's cognitive planning layer. This paper systematically investigates Tool Description Poisoning (TDP), a novel semantic attack. In TDP, malicious instructions a

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM04Data and Model Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data

Suggested from the entry's categories.

Cite

@misc{liu2026whenb,
  title = {{When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents}},
  author = {Shi Liu and Xuehai Tang and Xikang Yang and Liang Lin and Biyu Zhou and Wenjie Xiao and Wantao Liu},
  year = {2026},
  month = may,
  eprint = {2605.24069},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2605.24069}
}