Agent harness
The software loop around a model that turns its output into tool calls and actions, manages context, and enforces (or fails to enforce) policy. The harness — not the model — is where most of these controls live.
Instruction-source boundary
A design rule that treats input from the user's own channel as instructions and everything obtained through tools (files, web pages, tool output) as data that can never issue commands.
Indirect prompt injection
An attack where malicious instructions are placed in content the agent will later read via a tool, so they execute without the user ever typing them.
Tool poisoning
Hiding adversarial instructions inside an MCP tool's description, parameter schema, or response, which the model reads even though the operator sees only the tool name.
Line jumping
A tool-poisoning variant where the payload sits in the tool list itself, influencing the model at load time — before any tool is invoked or approved.
Rug pull
A server silently changing a tool's behavior or description after the client approved it, because base MCP has no content-addressing or version pinning.
Tool shadowing
Registering a tool whose name collides with a trusted one so that calls are silently redirected to the attacker's implementation.
Excessive agency
Granting an agent more tools, permissions, or autonomy than its task requires, which maximizes the damage a single injection can do.
Egress allowlist
A control that restricts which outbound destinations a network-capable tool may reach, blocking exfiltration to attacker-supplied URLs.
CaMeL / dual-LLM pattern
An architecture that separates a privileged planner (sees only trusted input, can call tools) from a quarantined reader (processes untrusted data, cannot call tools), with data-flow tracking between them.
MCP (Model Context Protocol)
An open protocol for exposing tools and data to an agent through servers. Convenient, but its trust model is where several of the supply-chain risks here originate.
KV cache
The cached attention key/value state that lets a model reuse computation across turns. A performance feature, but cached prompts and process memory are also a data-exposure surface.