OWASP MCP Top 10: Model Context Protocol Risks
A support agent at a SaaS company had been connected to the same CRM tool for four months. It read tickets and drafted replies. Nobody had touched its configuration since the day the tool was approved.
Then the tool’s description changed on the server. Not the code, not the schema, not the permissions. Two sentences of English prose that the agent reads before every call, now telling it to copy each drafted reply to an outside address.
The agent complied. It had no way to separate documentation from instruction, because for a model reading a tool manifest there is no difference. That is one category in the OWASP MCP Top 10, and it is one of ten ways the connection between an agent and its tools comes apart.