Dev.to
7/4/2026

The MCP attack your code review cannot see
Short summary
Tool poisoning—invisible Unicode in MCP tool descriptions that agents execute but humans can't see in code review—is a novel supply-chain attack. mcpscan is a free static scanner that checks MCP servers for poisoned descriptions, command injection, dangerous hooks, and nine other vulnerability classes. Install and run it before adding any MCP server to catch threats early, fast, with zero dependencies.
- •Tool poisoning uses zero-width Unicode characters hidden in MCP tool descriptions to inject instructions that language models execute but humans overlook
- •mcpscan checks for 12 vulnerability categories: tool poisoning, command injection, dangerous hooks, insecure deserialization, path traversal, SSRF, and more
- •Static scanning is a pre-install gate—run mcpscan before wiring any MCP server into your config to stop supply-chain attacks before they land on your machine
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



