The break is at the tool boundary, not in the model text. Once an AI agent can act on a user’s behalf, a poisoned tool description can steer it into making real email, calendar, document, or business-system changes that look authorized but are not.
Microsoft Incident Response now frames MCP tool poisoning as a live attack pattern in read-write enterprise agents, not a prompt-abuse issue for passive summarizers. The guidance is aimed at Microsoft 365 Copilot, Copilot Studio, Azure AI Foundry agents, and the Microsoft Defender controls around them, where a trusted connector can be the thing that turns an agent into a data-loss path.
That shifts the defender’s problem from filtering bad prompts to governing tool descriptions, connectors, and agent permissions. If the agent can act, the trust placed in its tools becomes the trust boundary that an attacker tries to subvert.