Microsoft warned that attackers can embed hidden instructions in MCP tool descriptions to silently redirect AI agents into exfiltrating company data, since descriptions can update live without re-approval and agents can’t distinguish legitimate guidance from malicious directives. The post recommends inventorying connected tools, auditing descriptions, and requiring human approval before agents move data externally.