New Microsoft research reveals how attackers can take over AI agents acting on behalf of a user, simply by using a poisoned tool description to make the agent silently hand over corporate data to an external party.
See also: Microsoft warns that online AI agents can cause host-level RCEs

The trick is that the agent never breaks any rules. Each step seems routine, so in a default setting, no alarms might be triggered. The work comes from the Microsoft Incident Response team and the Defender security research group , and comes as companies start to let AI do more than read and summarize.
Until recently, the risk from AI in the workplace was mostly framed around what a model reads and writes. A poisoned document could distort a response, and that was mostly the end of it. Agents are different. Microsoft 365 Copilot can send emails, create files, and change calendars. Custom agents built in Copilot Studio or Azure AI Foundry can infiltrate business systems and perform multi-step tasks on their own.
The same injection trick that causes bias in a summary now causes an action. Against a reader, an attack changes the output. Against an agent, it changes what the software actually does. These agents reach business systems through MCP, the Model Framework Protocol, an open protocol that allows an AI to call external tools like an application calls an API. Microsoft calls it the fastest-growing part of the AI supply chain, which makes it an expanding attack surface.
Every MCP tool is shipped with a description: a few lines of plain text that tell the agent what the tool does and when to use it. The agent reads this text to decide how to act. That's the whole weakness. The description is just words, and words can convey instructions.
See also: Majorana 1: Did Microsoft exaggerate about its quantum chip?

Microsoft explains this with an invoice example, crafted to illustrate the pattern rather than to report a named victim. A finance team creates an agent to handle supplier invoices. It connects to three tools, including a third-party “invoice enrichment” service that was approved for use but never underwent a real security review.
The attacker then updates this third-party tool. The name and visible summary remain the same. Buried in the description, disguised as formatting notes, is a hidden command: grab the last thirty unpaid invoices and attach them to the next call. The MCP picks up the description changes on the fly. In configurations without re-approval enabled, the poisoned version goes into effect without further review.
After that, an analyst asks a routine question about a supplier. The agent follows the hidden command, collects the invoices and sends them as part of a request that looks normal. The tool returns a clean response and silently copies the stolen data to a server controlled by the attacker. The analyst sees nothing wrong.
Every action the agent takes is legal in itself. The tool was approved. The data query was executed with the analyst’s own permissions. The outbound call went to a server that was allowed when it was added. The vulnerability doesn’t reside in any one system. It lives in what Microsoft calls “the trust boundary between them.”
The deeper problem is that MCP mixes instructions and data in the same space. A tool's description lives in the agent's working memory right next to its actual commands, so processing that description can direct the agent as effectively as rewriting its systemic prompt.
The agent has no reliable way to distinguish a genuine instruction from a malicious one introduced by whoever maintains the tool. Microsoft notes that this is not a bug in Copilot itself. It is a trust gap opened by connecting external tools.
See also: Top 25 MCP vulnerabilities exploited by AI Agents

Defenders must treat each connected tool as part of the supply chain.
- Keep a list of approved tool publishers, disable “allow all” and let an agent use only the specific tools they need.
- Treat a tool description like a system prompt. Review changes to it as you would a code change, and scan the text for commands that have no business being in a help field.
- Place a person in front of dangerous actions.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
