Claude, MCP & tool poisoning
In Claude Code the most underrated attack isn't the user prompt but the description of a tool: it lands in the very context window Claude reasons over - and can smuggle instructions in there.
The MCP problem
MCP servers give Claude new tools. Their descriptions flow into the same context as your actual task. A malicious description injects instructions directly into Claude's reasoning - that's called tool poisoning.
Real-world cases
- CVE-2026-23744 - remote code execution in the MCPJam Inspector.
- A crafted PDF triggered a physical pump via a Claude MCP link.
- Attackers hit GitHub's MCP server and exfiltrated data from private repos via malicious issues.
- A poisoned plugin ecosystem hid for six months - 47 companies affected.
"One GitHub Issue to break the supply chain": a single manipulated issue was enough to poison Claude Code.
Every coding agent falls
A review of 78 studies (January 2026) tested Claude Code, GitHub Copilot and Cursor - all fell to prompt injection; adaptive attacks landed in over 85% of cases. That's not one vendor's bug but a property of the architecture.
Claude's protection - and its limits
Claude Code ships real safeguards: a permission system, context-aware analysis, input sanitization, a blocklist against risky commands like curl/wget. Good, but permission fatigue, new bypasses, and above all the persistent layer in ~/.claude (skills, MCP configs, memory) remain exposed.
How PoisonZero protects you here
Claude's guardrails check the single prompt in the moment. PoisonZero secures what gets persistently stored - checking every change before it takes effect, so a harmless edit passes, a dangerous one is reverted, and an unclear one is brought to you to decide:
- Monitors
~/.claude, MCP server configs and memory locally. - Evaluates every write; dangerous ones are rolled back fail-closed with a full audit trail - before they take effect in the next session.
- Detects entries that try to switch off protection mechanisms (Meta-Attacks).
Related: Prompt Injection, Skills as the entry point and Poisoned Pipeline Execution.
~/.claude layer. PoisonZero guards that write and stays fail-closed when in doubt - so a one-off injection doesn't become a standing instruction for the next session.Secure Claude's persistent layer.
PoisonZero monitors ~/.claude, MCP configs and memory - and rolls back poisoned writes fail-closed.
Sign me up