Menu
← All posts

Sep 28, 2026

Tool poisoning: hidden instructions in tool content

How tool descriptions can redirect an agent, and what to review before connecting a server.

What it is

Tool poisoning places malicious instructions in content an agent reads, such as a tool description. Those instructions may try to change the task or make the agent reveal data.

What to review

Check who operates the server, which tools it exposes and what data those tools can access. Review changes to tool descriptions as well as code.

Limit the damage

Use trusted servers, narrow tool permissions and credentials with limited access. Content inspection can add another check, but no single control guarantees that an agent will ignore every malicious instruction.

See New Perimeter in action

Bring your agent use case. See where access is enforced and how every gateway decision can be reviewed.