My test suite was green. My detector was wrong.
I built a scanner to catch poisoned MCP tool descriptions, pointed it at 13,474 real ones, and watched it flag a tool called prompt_injection_scan as prompt injection.
Aug 10, 20269 min read30

Search for a command to run...
I built a scanner to catch poisoned MCP tool descriptions, pointed it at 13,474 real ones, and watched it flag a tool called prompt_injection_scan as prompt injection.

Standard load-testing phases by traffic volume. For an agent with third-party upstreams and multi-call turns, attribution is the harder problem.

Mocking the model lets you measure everything else. The model was the only thing that mattered.
