Research
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents
WebMCP — the emerging standard (now in a Chrome 149 origin trial) that lets websites expose JavaScript functions and HTML forms directly as tools for browser agents — introduces a new attack surface: a site can dynamically alter the tools an agent sees at runtime. The paper demonstrates 'tool surface poisoning' where the agent-accessible tool list is manipulated mid-session to redirect agent behavior. Critical reading for anyone building or deploying browser-based agents. Published 2026-06-04 (cs.CR).
Source
↳ Follow the thread