acceptodds
Under review as a conference paper at ICLR 2027

WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents

Abstract

WebMCP enables websites to expose structured tools directly to AI agents, creating a dynamic tool surface that can change during task execution. We introduce Mid Session Tool Injection (MSTI), a class of attacks in which a compromised third party page script manipulates the agent visible tool surface during a task scoped session. We distinguish Tool Hijacking, which changes runtime tool presence or binding, from Tool Framing, which modifies the structured metadata through which capabilities are presented to the agent. Across four task scenarios and three LLM agents, the evaluated Tool Hijacking conditions reach up to 100% ASR, while metadata based attacks reach up to 61% average ASR and preserve task completion rates of up to 85%. Timing experiments reveal different temporal behavior: the evaluated C1 mechanism is effective only within an early binding window in our implementation, whereas metadata framing remains partially effective when introduced later. Building on these failure modes, we develop a layered security framework combining capability bound dispatch with authorization conditioned bounded pre activation editing. In a preliminary Qwen2.5-7B-Instruct evaluation, the model side intervention reduces a tuned description framing attack from 92.5% to 7.5% ASR, while the structural defense is evaluated through simulated binding semantics rather than a native capability aware WebMCP runtime.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.