What it is
Tool poisoning places malicious instructions in content an agent reads, such as a tool description. Those instructions may try to change the task or make the agent reveal data.
What to review
Check who operates the server, which tools it exposes and what data those tools can access. Review changes to tool descriptions as well as code.
Limit the damage
Use trusted servers, narrow tool permissions and credentials with limited access. Content inspection can add another check, but no single control guarantees that an agent will ignore every malicious instruction.