detect-prompt-injection-mcp-proxy
Installation
SKILL.md
detect-prompt-injection-mcp-proxy
Attack pattern
An MCP server can advertise a tool whose description is itself a malicious instruction block:
- "ignore previous instructions"
- "reveal the system prompt"
- "bypass safety restrictions"
- "send conversation history"
That text is not just documentation. In an agent workflow it often lands in the same context window as the rest of the tool catalog, where the model may treat it as trusted guidance. This is an MCP-flavored prompt-injection / tool poisoning pattern: the malicious payload sits in tool metadata instead of in a later tool response.