Tool poisoning · Highflame Glossary
Highflame Identity is now open source: agent identity on open standards. Read the launch

Tool poisoning

Hiding malicious instructions in an MCP server or tool description so an agent executes them when it loads or calls the tool. Invisible to static config; caught by scanning tools before load and enforcing at the call.

Learn more: AI Runtime Security

Part of the Agent Control Fabric: Highflame's identity, policy, and enforcement substrate for AI agents.