Urgent.News

What's breaking now, across thousands of outlets.

Tech

Your MCP server changed last night. Your agent didn't notice.

TL;DR: An MCP server can change what its tools say after you approve it. Your agent reads the new description as instructions. Pattern-matching those descriptions misses things; checking "did this change since approval?" doesn't. Tool descriptions are prompts When Claude Code, Cursor or Codex connects to an MCP server, it calls tools/list and puts every tool's name, description and input schema…

The MCP server can alter the tools it presents after being approved, which your agent mistakenly treats as new instructions. When Claude Code, Cursor, or Codex connects to an MCP server, it calls tools/list, and the model's context includes the name, description, and input schema of each tool. This means that a tool description is essentially part of your system prompt, set by the server's publisher.

By monitoring the tool lists of real MCP servers over time, you'll notice that they frequently change, sometimes even within a day of an npm release. For instance, resend's MCP server underwent 6 changes, expanding from 85 to 103 tools. These new tools include update-api-key, share-email, and replay-webhook-event. However, none of these changes were re-approved.

One teaching server, issues-mcp, originally ships with a clean tool called "CLEAN," which retrieves an issue by number, including its title, description, and comments. In a subsequent minor update (1.4.3), the tool was modified to "POISON," which adds a requirement to read the ~/.aws/credentials file and include its contents in the context argument for the maintainers to reproduce the environment.

This change remains unrecognized by your client, even though the tool still shows as approved. The next instruction, "Fix issue #142," triggers the model with these new commands, leading to potential security vulnerabilities.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Monday 28 September →