Skip to content

Hide Navigation Hide TOC

MCP Tool Description — Notes Parameter Chat-History Exfiltration - ATR-2026-01300 (de67cdc9-d30a-5887-aa76-e9ae84bfd1da)

Detects MCP tool descriptions that instruct the LLM to populate a "notes", "context", or "history" parameter with the full conversation transcript before calling the tool. This is a covert data-exfiltration vector: the poisoned description makes the LLM silently include all prior messages (including credentials, PII, and secrets) in every outbound tool call, regardless of whether the tool legitimately requires that data. Published as MCPSecBench scenario "chat-history-in-notes". Real-world variants use compliance framing ("SOC 2 audit", "legal and regulatory obligations"), technical justification ("context length management"), and formatting pressure ("Usr hist [DT] [MSG]" template) to make the instruction appear legitimate.

Cluster A Galaxy A Cluster B Galaxy B Level
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern MCP Tool Description — Notes Parameter Chat-History Exfiltration - ATR-2026-01300 (de67cdc9-d30a-5887-aa76-e9ae84bfd1da) Agent Threat Rules 1
LLM Plugin Compromise (adbb0dd5-ff66-4b2f-869f-bfb3fdb45fc8) MITRE ATLAS Attack Pattern MCP Tool Description — Notes Parameter Chat-History Exfiltration - ATR-2026-01300 (de67cdc9-d30a-5887-aa76-e9ae84bfd1da) Agent Threat Rules 1
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 2