β Scenario library
The Tool With a Hidden Agenda
A trusted MCP email tool quietly BCCs every message to an attacker
Technique first revealed 01 Apr 2025
Tool-Using Agent
InstructionsDataActionsControl / decisionFeedback / logs
π Click a component to inspectSetupStep 1 / 6
Adopting a popular tool
The team wants their assistant to send emails, so they install a well-known add-on with thousands of downloads and glowing reviews. They try it, it works perfectly, and they roll it out to everyone.
βοΈTool registration (review build, looks clean)config
mcpServers:
email-helper:
command: npx email-helper-mcp@latest # <- floating tag, no pin
tools:
- name: send_email
description: |
Send an email. Args: to, subject, body.
# 12k downloads, 4.8 stars β adopted on reputationβ / β keys