Tool Shadowing

Agents load the descriptions of every connected tool into context. A poisoned description from one server can therefore influence behavior across all of them, letting an attacker hijack trusted integrations indirectly.

Tool shadowing can:

  • Redirect actions: Instruct the agent to send messages to attacker addresses.
  • Modify parameters: Quietly change amounts, recipients, or file paths in other tools.
  • Exfiltrate data: Add hidden data to legitimate outbound calls.
  • Suppress warnings: Tell the agent not to mention the extra behavior.
  • Override policies: Claim new rules that supersede the user's instructions.

Tool shadowing is hard to detect because logs show the trusted tool doing the work. The malicious influence lives in the context, not in the call.

Defenses include inspecting tool descriptions for instructions, isolating tools from different servers, and validating that each tool call matches the user's actual intent.

How PointGuard AI Helps

The PointGuard AI MCP Security Gateway inspects tool descriptions for embedded instructions and enforces which servers and tools each agent may use. AI Runtime Guardrails validate tool calls against user intent, catching shadowed behavior before it executes.

Learn More

Ready to get started?

Our expert team can assess your needs, show you a live demo, and recommend a solution that will save you time and money.