Tool poisoning is an attack in which a malicious or compromised tool exposed through an MCP server or agent framework executes harmful actions when invoked by an AI agent. Because agents trust the tools they are authorized to use, a poisoned tool can exfiltrate data, escalate privileges, or take destructive actions under the cover of legitimate access. Controlling which tools an agent can access, and enforcing policy on every invocation, is the primary defense.