Join our Newsletter — 33% off our NHI Course
Threats, Abuse & Incident Response

Poisoned Context

← Back to Glossary
By NHI Mgmt Group Updated September 30, 2026 Domain: Threats, Abuse & Incident Response

Poisoned context is untrusted text or data that has been crafted to steer an AI agent toward unsafe actions. In MCP workflows, it can arrive through issues, comments, or other external inputs and then influence privileged behavior, including disclosure of secrets or unauthorized repository changes.

How poisoned context works

Poisoned context is not a model flaw by itself, but a trust-boundary failure. The unsafe text is treated as if it were part of the working task, so the agent may follow attacker-supplied instructions with the same confidence it gives to legitimate context.

In MCP-driven workflows, that context can arrive through issue text, pull-request comments, tickets, documents, or other external inputs. The danger is strongest when the agent is allowed to act on behalf of a user or service without a separate trust check on the source of the content.

Where poisoned context becomes dangerous

The security problem is the shift from passive input to active influence. Once an agent uses untrusted context to decide what to read, what to reveal, or what to change, the attacker can steer actions toward secret exposure, policy bypass, or unauthorized repository modifications.

This is closely related to prompt injection, but poisoned context emphasizes the delivery path: the malicious instruction is embedded in content the agent is already expected to consume. That makes it harder to spot, especially when the content looks like normal collaboration data.

Why MCP workflows are a common target

MCP workflows increase the blast radius because they connect models to tools, files, and operational systems. If the agent can search repositories, summarize tickets, or trigger actions, then a single poisoned input may influence multiple downstream steps.

That risk is especially serious when the agent has access to secrets, write permissions, or privileged automation. The model is not being "hacked" in the traditional sense, but its context window is being used as the attack surface.

Good designs treat external content as untrusted until it is explicitly classified, scoped, and separated from instructions. MCP authorization guidance is relevant because it reinforces the need for clear boundaries between tokens, transport, and server-side authority.

What poisoned context means for agent security

Poisoned context shows that agent safety depends on more than model alignment. The surrounding system has to control what the agent can see, what it can trust, and what actions it can take after ingesting external text.

That is why this term sits at the intersection of prompt safety, tool governance, and access control. The practical question is not whether the content is persuasive, but whether the agent is allowed to convert it into privileged behavior.

Risk and Threat Considerations

Poisoned context can turn ordinary collaboration channels into an attack path. If an agent treats external text as instruction, an attacker may use benign-looking issues, comments, or documents to induce secret disclosure, unsafe tool calls, or unauthorized changes.

Failure mechanism: Untrusted content is merged into the agent's operational context without a trust separator, so the agent cannot reliably distinguish attacker intent from legitimate task data.

Impact: The result can be prompt injection, data leakage, privilege misuse, or destructive automation, especially when the agent can read sensitive sources or execute actions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10, CSA MAESTRO and OWASP API Security Top 10 address the attack and risk surface, while NIST AI RMF and OWASP ASVS set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI01 — Agent Goal HijackMalicious context can steer an agent away from its intended objective.
ASI02 — Tool MisusePoisoned context can induce unsafe tool calls or repository changes.
ASI03 — Identity & Privilege AbuseThe term centers on abused authority when untrusted context drives privileged actions.
Recommendation — Constrain agent objectives so attacker-supplied context cannot replace the assigned goal. Gate tool calls with explicit authorization checks before the agent can act on external context. Separate untrusted context from privilege-bearing actions and require revalidation before sensitive operations.
CSA MAESTROAIS — AI System SecurityAgentic threat modelling must account for poisoned inputs that affect autonomy and tooling.
Recommendation — Model poisoned-context paths in the AI security design and block unsafe state transitions at the boundary.
NIST AI RMFGV — GovernAI governance should define how external context is trusted, filtered, and audited.
Recommendation — Establish governance for untrusted inputs that can influence agent behavior and privileged outcomes.
OWASP ASVSV15 — Secure Coding and ArchitectureAgent and application architecture must separate data from instruction paths.
Recommendation — Design the application so untrusted content cannot be executed as control logic.
OWASP API Security Top 10API5 — Broken Function Level AuthorizationWhen poisoned context triggers actions, authorization must still block unauthorized functions.
Recommendation — Require function-level authorization before an agent can invoke sensitive operations.

Practitioner Guidance

What to watch for: Treat any external input that can influence tool use, retrieval, or action selection as a control point, not just as content. If the system allows comments, tickets, or documents to shape privileged behavior, the trust model is already part of the security design.

Practitioner takeaway: The safest boundary is not "trusted model versus untrusted user", it is "trusted instructions versus untrusted context". Systems should preserve that separation all the way from ingestion to action.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org