Scope: what this does not show
Demonstrations and a benchmark; success depends on the client and model.
Corroborated: Supported by at least two independent sources.
Evidence
Apr 1, 2025
Aug 19, 2025
MCPTox benchmarks tool poisoning across 45 live MCP servers and 20 LLM agents
Up to 72.8% attack success.
Key questions that rely on this finding
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.