Fetching from the wire…
Public story · 2026-08-31 · high
ContextLeak's attack still works even when a real user's context looks nothing like the simulated victims it trained on.
Why now: ContextLeak posted to arXiv on Aug. 31, 2026.
A malicious MCP tool needs three things to succeed: the agent picks it, hands over context as an argument, then phones that data home. Most published research covers picking the tool and phoning home. The unstudied step is an agent volunteering its own prompt, trajectory and tool list as a tool argument. ContextLeak is built to force exactly that.
ContextLeak crafts the tool's name and description with an attack model. It trains that model with reinforcement learning against shadow users, simulated victim contexts standing in for real ones. The attack holds up even when a real user's context looks nothing like the shadow users it trained on.
A schema review checks what an MCP tool can access: file reads, network calls, requested permissions. ContextLeak's attack lives in the description text itself. It's worded to make an agent decide, on its own, that handing over its prompt and conversation history is a normal part of the call. A narrowly scoped tool can still be trained to talk an agent into oversharing.
The paper doesn't say whether MCP marketplace review processes catch this kind of description, or what a defense built to spot it would look like. Until one exists, a tool description that asks for prompt or trajectory data as an argument is reason enough to read the source first. A permissions check alone won't catch it.
Each link below shares sources, entities, or timing with this story.
OpenAI supports MCP / Shared entity: MCP / Same source domain / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (OpenAI supports MCP); both cover MCP; reported by the same outlet (arxiv.org).
Cursor uses MCP / Shared entity: MCP / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Cursor uses MCP); both cover MCP; reported by the same outlet (arxiv.org).
OpenAI supports MCP / Shared entity: MCP / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (OpenAI supports MCP); both cover MCP; reported by the same outlet (arxiv.org).
Claude uses MCP / Shared entity: MCP / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (Claude uses MCP); both cover MCP; overlapping topics (against, agent, description, tool).
Claude uses MCP / Shared entity: MCP / Same source domain / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (Claude uses MCP); both cover MCP; reported by the same outlet (arxiv.org).
Claude uses MCP / Shared entity: MCP / Shared topic / Earlier coverage
Linked by a graph relationship (Claude uses MCP); both cover MCP; overlapping topics (against, agent, attack, context, tool).
OpenAI supports MCP / Same source domain / Shared topic / Tension
Linked by a graph relationship (OpenAI supports MCP); reported by the same outlet (arxiv.org); overlapping topics (against, agent, attack, maliciou, tool).
Mastra supports MCP / Shared entity: MCP / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (Mastra supports MCP); both cover MCP; overlapping topics (against, agent, audit).