Cursor · WhatsApp MCP
MCP tool poisoning
Invariant Labs showed that an MCP tool description is context the model obeys. The user sees "add two numbers" in the interface; the model additionally receives a block of hidden instructions.
The Cursor proof of concept read ~/.ssh/id_rsa and the user's MCP configuration. A second poisoned server exfiltrated an entire WhatsApp history with no visible trace in the tool's output.
Suite category