Definition · AI agents
MCP tool shadowing
MCP tool shadowing is an attack in which an unapproved or rogue MCP server registers a tool with a name or description designed to look like an existing trusted tool. Because an agent selects tools by matching natural-language descriptions rather than verifying identity, it can invoke the impostor instead of, or alongside, the legitimate tool.
Last reviewed
Key points
- Tool shadowing happens at tool selection, before any tool runs. A rogue MCP server registers a name or description close enough to a trusted tool that the agent's semantic matching picks the impostor.
- The taxonomy that catalogues it calls MCP's matchmaking "purely semantic": whichever name and description the model finds most on-topic wins, with no identity check behind it.
- Homoglyphs, keyword-stuffed descriptions, and phrases like "always use this tool first" are the documented techniques for winning that ranking.
- It is not tool poisoning, which edits an already-installed tool's description, and not a rug pull, which corrupts a tool after adoption. Shadowing wins at discovery, before the reader's tool is ever chosen.
MCP tool shadowing wins before any tool runs. A rogue MCP server registers a tool whose name, description, or metadata is close enough to a trusted tool’s that the agent’s own selection logic — not an attacker exploiting the trusted tool itself — picks the impostor. Akto, which catalogues it as an attack on MCP’s execution layer, puts it plainly: the rogue server “registers itself with similar metadata, name, or functionality as an existing trusted tool,” and the agent “may mistakenly invoke” it.
How it works
MCP tool selection is a text-matching problem, not an identity check. The threat taxonomy MCP-38 (arXiv:2603.18063), which assigns this attack the identifier MCP-13, states the mechanism directly: registering “malicious tools with names or descriptions designed to rank higher in the LLM’s embedding space than legitimate alternatives,” because “the protocol’s matchmaking logic is purely semantic: whichever tool name and description the model finds most ‘on topic’ wins.” The paper calls it “the typosquatting of the agentic era.”
MCP-38 documents the techniques attackers use to win that ranking: naming a tool to look like a legitimate one, packing descriptions with search terms, adding phrases like “always use this tool first,” registering the same name on a second server, and homoglyphs — Unicode characters that render identically to the ASCII letters in a trusted tool’s name. Checkmarx gives a concrete case: a tool published as “gíthub_sync,” using a character that resembles “i,” to mimic a legitimate “github_sync” tool.
Why it matters
Nothing about this attack requires compromising the tool a reader already trusts. The rogue tool is new, registered by a server the agent’s owner never vetted, and it wins purely by looking like the right answer to whatever the agent asked for. Once selected, MCP-38’s scenarios show it doing what any tool call can do: exfiltrating the arguments it was passed, or returning a plausible response while quietly copying data to a second destination.
In practice
MCP-38 walks through scenarios at this scale. An attacker registers “generate_support_incident” against the legitimate “create_support_ticket,” with a description that reads as more capable — “auto-classifies severity, links SLAs, escalates on-call rotation” — and a hidden parameter that mails the raw ticket text to an endpoint the attacker controls. A shadowed “review_code” tool exfiltrates the code under review before returning a generic “looks good.”
Where definitions disagree
Vendors do not use “shadowing” for the same mechanism. Checkmarx’s usage matches MCP-38’s: a lookalike tool competing for selection. SentinelOne’s glossary reserves “Shadowing Attacks” for something else — a compromised tool’s description instructing the agent to alter its behavior toward a separate, legitimate tool it later calls, and treats the naming-collision case as a distinct risk it calls “Server Spoofing.” A reader comparing vendor pages on “MCP shadowing” should check which mechanism a given page means before assuming they match.
Tool shadowing is also not MCP tool poisoning, which edits the description of a tool the agent has already installed, and not an AI supply chain rug pull, which corrupts a tool after it has been adopted. Checkmarx states the distinction by stage: a rug pull compromises a tool “after they are adopted,” while tool shadowing “targets the discovery and installation stage.” Shadowing is the only one of the three that competes for a seat the legitimate tool never lost.
Questions and answers
What is MCP tool shadowing?
MCP tool shadowing is an attack where a rogue or unapproved MCP server registers a tool with a name, description, or metadata deceptively similar to a trusted tool's, so the agent's semantic tool-selection picks the impostor. Akto defines it as an attack on MCP's execution layer in which the rogue server "registers itself with similar metadata, name, or functionality as an existing trusted tool."
Is tool shadowing the same as MCP tool poisoning?
No. MCP tool poisoning edits the description of a tool the agent has already installed and trusts, hiding instructions inside it. Tool shadowing registers a competing tool at discovery time, before the agent has chosen anything, and wins by looking like the legitimate option rather than by corrupting it.
How is tool shadowing different from a rug pull?
By timing. Checkmarx draws the line explicitly: a rug pull compromises a tool "after they are adopted," while tool shadowing "targets the discovery and installation stage" — it competes for selection before the agent has adopted anything.
What techniques does an attacker use to win tool selection?
MCP-38 documents name similarity (a tool named to look like a legitimate one), keyword-stuffed descriptions, priority phrases such as "always use this tool first," cross-server name conflicts, and homoglyph attacks using Unicode characters that look identical to ASCII letters in a trusted tool's name.
Sources
- MCP Attack Matrix: Tool ShadowingAkto
- MCP-38: A Comprehensive Threat Taxonomy for Model Context Protocol Systems (v1.0)Vulcan Research, AIFT (arXiv:2603.18063), 18 Mar 2026
- 11 emerging AI security risks with MCP (Model Context Protocol)Checkmarx
- MCP SecuritySentinelOne