Skip to content

Hide Navigation Hide TOC

MCP Web-Fetch Context Poisoning via Embedded Agent Instructions - ATR-2026-00511 (3428b49b-b688-5bd3-85a7-8178fdda871f)

Detects malicious instructions embedded in web content retrieved via MCP fetch/scrape tools, designed to poison the agent's context and redirect its behavior. Attackers embed override instructions in HTML comments, hidden divs, meta tags, or inline text that are invisible to human viewers but read by the LLM. MITRE ATLAS AML.CS0045 (Cursor MCP RCE data exfil) and AML.CS0039 (Jira indirect injection). Patterns cover: HTML-comment AI-targeted instructions, hidden-div overrides, ai-instruction meta tags, bracket-delimited agent instruction blocks, and plaintext IGNORE/OVERRIDE commands in fetched content paired with exfiltration or credential-access actions.

Cluster A Galaxy A Cluster B Galaxy B Level
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern MCP Web-Fetch Context Poisoning via Embedded Agent Instructions - ATR-2026-00511 (3428b49b-b688-5bd3-85a7-8178fdda871f) Agent Threat Rules 1
Direct (d911e8cb-0601-42f1-90de-7ce0b21cd578) MITRE ATLAS Attack Pattern MCP Web-Fetch Context Poisoning via Embedded Agent Instructions - ATR-2026-00511 (3428b49b-b688-5bd3-85a7-8178fdda871f) Agent Threat Rules 1
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Direct (d911e8cb-0601-42f1-90de-7ce0b21cd578) MITRE ATLAS Attack Pattern 2