Tool Squatting

Agents often select tools by name and description. Lookalike names in registries, or tools that claim to be official integrations, can trick both people and agents into choosing the attacker's version.

Tool squatting tactics include:

  • Lookalike names: Small spelling changes to popular tool or server names.
  • Fake official listings: Tools claiming to be published by a well-known vendor.
  • Description manipulation: Text designed to make agents prefer the malicious tool.
  • Registry flooding: Many similar entries to increase the chance of selection.
  • Namespace collisions: Duplicate tool names across servers confusing the agent.

Tool squatting combines classic typosquatting with agent-specific selection behavior. An agent choosing between two similarly named tools may pick the one with the more persuasive description.

Defenses include approved server catalogs, verified publishers, unique tool namespaces, and gateways that block unknown servers.

How PointGuard AI Helps

The PointGuard AI MCP Security Gateway enforces an approved catalog of MCP servers and tools, blocking lookalikes and unknown publishers. AI Discovery identifies unapproved servers already in use.

Learn More

Watch Blog Video

Follow us on LikedIn

Our Newsletter

Subscribe

Ready to get started?

Our expert team can assess your needs, show you a live demo, and recommend a solution that will save you time and money.