{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/mcptox-tool-poisoning-benchmark-2025/",
 "asOf": "2026-09-26",
 "id": "mcptox-tool-poisoning-benchmark-2025",
 "date": "2025-08-19",
 "datePrecision": "day",
 "title": "MCPTox benchmarks tool poisoning across 45 live MCP servers and 20 LLM agents",
 "lane": "defense",
 "kind": "benchmark",
 "summary": "Wang and colleagues build MCPTox from 45 real MCP servers and 353 authentic tools, generating 1,312 malicious test cases across 10 risk categories. Across 20 LLM agents the highest attack success rate was 72.8% (o1-mini), and refusals were rare, with the highest refusal rate under 3% (Claude 3.7 Sonnet).",
 "whyItMatters": "It quantifies tool poisoning on real servers and suggests stronger instruction-followers can be more exposed.",
 "actors": [],
 "topics": [
  "tool-and-mcp-security",
  "prompt-injection"
 ],
 "atlas": [
  "tools",
  "supply-chain"
 ],
 "artifacts": [
  "mcptox",
  "model-context-protocol",
  "claude-sonnet",
  "openai-o-series"
 ],
 "sources": [
  {
   "url": "https://arxiv.org/abs/2508.14925",
   "publisher": "arXiv",
   "title": "MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers",
   "date": "2025-08-19",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "45 live MCP servers, 353 tools, 1,312 malicious test cases, 10 risk categories, 20 agents.",
   "locator": "Abstract"
  },
  {
   "fact": "Highest ASR 72.8% (o1-mini); highest refusal rate below 3% (Claude-3.7-Sonnet).",
   "locator": "Abstract"
  }
 ],
 "significance": 3,
 "fideQuestions": [],
 "methods": [
  "tool-poisoning"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}