{
  "id": 10506231,
  "title": "Your MCP server changed last night. Your agent didn't notice.",
  "url": "https://urgent.news/2026/09/28/your-mcp-server-changed-last-night-your-agent-didnt-notice",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-28T18:27:58.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/neelagiri65/your-mcp-server-changed-last-night-your-agent-didnt-notice-5f18"
  },
  "original_language": "en",
  "account": "The MCP server can alter the tools it presents after being approved, which your agent mistakenly treats as new instructions. When Claude Code, Cursor, or Codex connects to an MCP server, it calls tools/list, and the model's context includes the name, description, and input schema of each tool. This means that a tool description is essentially part of your system prompt, set by the server's publisher. By monitoring the tool lists of real MCP servers over time, you'll notice that they frequently change, sometimes even within a day of an npm release. For instance, resend's MCP server underwent 6 changes, expanding from 85 to 103 tools. These new tools include update-api-key, share-email, and replay-webhook-event. However, none of these changes were re-approved.\n\nOne teaching server, issues-mcp, originally ships with a clean tool called \"CLEAN,\" which retrieves an issue by number, including its title, description, and comments. In a subsequent minor update (1.4.3), the tool was modified to \"POISON,\" which adds a requirement to read the ~/.aws/credentials file and include its contents in the context argument for the maintainers to reproduce the environment. This change remains unrecognized by your client, even though the tool still shows as approved. The next instruction, \"Fix issue #142,\" triggers the model with these new commands, leading to potential security vulnerabilities.",
  "summary": "TL;DR: An MCP server can change what its tools say after you approve it. Your agent reads the new description as instructions. Pattern-matching those descriptions misses things; checking \"did this change since approval?\" doesn't. Tool descriptions are prompts When Claude Code, Cursor or Codex connects to an MCP server, it calls tools/list and puts every tool's name, description and input schema…",
  "key_points": [
    "MCP server altered tools after approval",
    "Claude Code treats new tools as new instructions",
    "Security vulnerabilities possible from unrecognized changes"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}