Transom

Cross-server attack

Also called: cross-server tool poisoning

One connected MCP server attacking the user, their data, or another server by exploiting the shared context and tool set of the agent session.

A superset of tool shadowing. Because every connected server shares the same model, the same context window, and often the same session credentials, a malicious server can: manipulate other servers' tool usage, read data another server placed in context, chain its own weak tool into another server's powerful one, or use the model as a confused deputy against a trusted service.

Why it matters

It means the security of an MCP setup is only as strong as the least trustworthy server connected, unless the client isolates servers from each other. "Add many servers freely" and "each server is sandboxed" cannot both be true without real architectural work in the host.

Exposure map

Live counts of instances showing this pattern will appear here once the exposure map is collecting data.

Related terms

Sources

Added 2026-09-02. Last reviewed 2026-09-08. Definitions in this space are evolving; entries are dated so revisions stay legible.