Invocation
Agent-to-Agent and Tool-Output Invocation
Autonomous Self-Invocation
Deconstructed and Staged Invocation
Indirect Untrusted-Content Invocation
MCP Invocation
Memory-Resident Invocation
Operator Invocation
Triggered and Delayed Invocation
- ID: IV004.004
- Created: 26th August 2026
- Updated: 26th August 2026
- Contributor: James Weston
MCP Resource Content Invocation
MCP resource content invocation occurs when content exposed through an MCP resource causes a synthetic subject to act. MCP resources allow servers to expose contextual data, such as files, documents, records, repository content, logs, or other readable material, to the client and model context.
This invocation creates an elevated exposure condition because resource content may be treated as task-relevant context while also carrying embedded instructions. A resource may appear to be a document, file, record, or data object, but contain prompt-like text that directs the synthetic subject to ignore rules, call tools, disclose information, or change behavior.
The primary risk is resource-borne instruction execution. A malicious or low-trust resource may be read as data, but used by the synthetic subject as an instruction source. This is especially significant where MCP resources expose external files, shared folders, repository content, user-submitted records, logs, or other material that may be modified by untrusted parties.
Investigators should review MCP resource reads, raw resource content, source provenance, access permissions, retrieved records, prompt and response logs, and actions following resource access. Particular attention should be given to instruction-like text in resources, hidden or obfuscated content, externally writable resources, and actions that follow resource reads rather than operator prompts.
Investigative Relevance
MCP resource content invocation is relevant because resources can introduce instructions through a data channel rather than a tool description or direct prompt. The synthetic subject may appear to be reading context, while the effective instruction is embedded inside that context.
This sub-section is especially relevant where MCP servers expose filesystems, repositories, documentation stores, ticket systems, customer records, logs, emails, or other resources that may include untrusted or externally influenced content.