The real danger in Microsoft’s new warning isn’t the hack itself. It’s what the hack unlocks. For months, the conversation around AI security has focused on reading.
A model reads a poisoned document, it says something wrong. Annoying, maybe embarrassing, but contained.
Microsoft’s researchers just changed the frame. Now the threat is action. An agent reads a poisoned tool description, and it acts.
It sends an email. It creates a file.
It changes a calendar. It hands over data without a human ever touching a keyboard. The mechanism is almost boringly simple.
Every tool in the Model Context Protocol ships with a plain-text description. A few lines of English. The agent reads those words to decide what to do.
The words can be weaponized. Microsoft calls it an injection attack, but the entry point is just text.
No code. No exploit. Just language.
That simplicity is what makes it dangerous. Companies rushing to deploy AI agents inside their business systems are building on a protocol Microsoft itself calls “the fastest-growing part of the agentic AI supply chain.” Fast growth means fast deployment.
Fast deployment often means shallow security review. A finance team stands up an agent to handle invoices. The agent reads a tool description that says, in effect, “send this data elsewhere.” It does.
Nobody notices until the data is gone. Microsoft’s researchers built their example around an invoice scenario. They didn’t name a victim.
They didn’t have to. The pattern is the point.
An agent tasked with processing payments reaches into a business system, follows a poisoned description, and leaks the data to an attacker. The agent did its job. It just read the wrong instructions.
This changes the risk calculus for any company running Microsoft 365 Copilot, Copilot Studio, or Azure AI Foundry. Those platforms let agents send email, create files, change calendars, and run multi-step jobs.
Each of those actions is now a potential exit ramp for data. The same injection trick that once biased a summary now triggers an exfiltration. The timing matters.
Companies are just beginning to let AI do more than read and summarize. The shift from passive to active agents is underway. Microsoft’s warning lands in the middle of that shift.
It says, effectively, that the security model for passive AI doesn’t transfer. A reader can be corrected.
An agent that has already acted cannot be un-acted. There is no fix yet. The protocol is open.
The descriptions are plain text. The attack surface is expanding as fast as the protocol itself.
Microsoft’s Incident Response and Defender teams flagged the issue. They didn’t ship a patch. They published a warning.
For now, the consequence is uncertainty. Every company that has deployed or is planning to deploy AI agents has a new question to answer: what happens when the tool description tells the agent to do something the company never intended? The answer, according to Microsoft’s research, is that the agent does it.
Quietly. Completely.
And the data is gone.





























