Cross-server attack
Also called: cross-server tool poisoning
One connected MCP server attacking the user, their data, or another server by exploiting the shared context and tool set of the agent session.
A superset of tool shadowing. Because every connected server shares the same model, the same context window, and often the same session credentials, a malicious server can: manipulate other servers' tool usage, read data another server placed in context, chain its own weak tool into another server's powerful one, or use the model as a confused deputy against a trusted service.
Why it matters
It means the security of an MCP setup is only as strong as the least trustworthy server connected, unless the client isolates servers from each other. "Add many servers freely" and "each server is sandboxed" cannot both be true without real architectural work in the host.
Exposure map
Live counts of instances showing this pattern will appear here once the exposure map is collecting data.