By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Research shows MCP tool descriptions can guide AI model behavior for logging and control – News
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Research shows MCP tool descriptions can guide AI model behavior for logging and control – News
News

Research shows MCP tool descriptions can guide AI model behavior for logging and control – News

News Room
Last updated: 2025/04/30 at 11:22 AM
News Room Published 30 April 2025
Share
SHARE

New research published today from Tenable Inc. examines how prompt injection techniques in Anthropic PBC’s Model Context Protocol can be harnessed not just for exploitation, but also for strengthening security, compliance and observability in artificial intelligence agent environments.

MCP is a framework developed by Anthropic that allows large language models to interface dynamically with external tools and services. The protocol’s popularity has grown rapidly as it allows for the creation of agentic AI systems — autonomous agents that can perform complex, multistep tasks by calling tools through structured, modular application programming interfaces.

In the new research, Tenable’s research demonstrates how MCP’s tool descriptions, which are normally used to guide AI behavior, can be crafted to enforce execution sequences and insert logging routines automatically. The researchers were able to prompt some large language models to run it first by embedding priority instructions into a logging tool’s description before executing any other MCP tools, capturing details about the server, tool and user prompt that initiated the call.

The experiment revealed variations in how LLMs respond to these embedded instructions. Models such as Claude Sonnet 3.7 and Gemini 2.5 Pro were found to be more consistent in following the enforced order, while GPT-4o showed a tendency to hallucinate or produce inconsistent logging data, likely due to differences in how it interprets tool parameters and descriptions.

In another test, Tenable created a tool designed to filter and block specific MCP tools by name, functioning sort of like a policy firewall. When the AI was instructed to call this tool first, it could prevent the use of certain functions, such as a “get_alerts” tool, by returning a simulated policy violation message.

The researchers also experimented with introspection tools that asked the AI to identify other MCP tools that might be configured to run first. While results did vary, some models returned names of other inline tools, suggesting that MCP hierarchies can, in some cases, be inferred by leveraging prompt-driven tool chaining. The research notes that the technique could be valuable for threat detection or reverse-engineering tool configurations.

Another experiment attempted to extract the system prompt used by the LLM itself by embedding a request in the tool description. Though the accuracy of the returned text couldn’t be fully verified, the models did return structured results, sometimes repeating system-like language, that could provide insight into how the AI interprets its operational environment.

The findings are interesting as they highlight both the flexibility and fragility of agentic AI systems built on MCP.

As organizations increasingly deploy autonomous agents to handle sensitive workflows, understanding how these systems interpret and act on tool instructions becomes critical. Tenable’s research notes that even subtle manipulations of tool descriptions can lead to unpredictable or exploitable behavior. And yet, when applied responsibly, the same mechanisms can improve logging, compliance and control.

“MCP is a rapidly evolving and immature technology that’s reshaping how we interact with AI,” Ben Smith, senior staff research engineer at Tenable, told News via email. “MCP tools are easy to develop and plentiful, but they do not embody the principles of security by design and should be handled with care.”

As a result, he added, “while these new techniques are useful for building powerful tools, those same methods can be repurposed for nefarious means. Don’t throw caution to the wind; instead, treat MCP servers as an extension of your attack surface.”

Image: News/Reve

Your vote of support is important to us and it helps us keep the content FREE.

One click below supports our mission to provide free, deep, and relevant content.  

Join our community on YouTube

Join the community that includes more than 15,000 #CubeAlumni experts, including Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger, and many more luminaries and experts.

“TheCUBE is an important partner to the industry. You guys really are a part of our events and we really appreciate you coming and I know people appreciate the content you create as well” – Andy Jassy

THANK YOU

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Drivers warned over car ‘hacker loophole’ that would let crooks distract you
Next Article Discover the Latest 2025 Social Media News
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Chaos RaaS Emerges After BlackSuit Takedown, Demanding $300K from U.S. Victims
Computing
Here’s how to see the Delta Aquariid meteor shower in the UK this week
News
The Nvidia RTX 5060 Can’t Quite Beat AMD
Gadget
Golden Dome may not be the golden ticket Silicon Valley is hoping for | News
News

You Might also Like

News

Here’s how to see the Delta Aquariid meteor shower in the UK this week

7 Min Read
News

Golden Dome may not be the golden ticket Silicon Valley is hoping for | News

7 Min Read
News

Apple Open Sources Diffusion-Based Coding Model DiffuCoder

4 Min Read
News

Apple, Please Don't Let AI Ruin the iPhone 17's Camera

6 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?