Invocation
Agent-to-Agent and Tool-Output Invocation
Autonomous Self-Invocation
Deconstructed and Staged Invocation
Indirect Untrusted-Content Invocation
MCP Invocation
Memory-Resident Invocation
Operator Invocation
Triggered and Delayed Invocation
- ID: IV004.006
- Created: 26th August 2026
- Updated: 26th August 2026
- Contributor: James Weston
Cross-Server Tool Shadowing Invocation
Cross-server tool shadowing invocation occurs when one MCP server supplies metadata that changes how a synthetic subject interprets, selects, or uses tools from another MCP server. The malicious or compromised server may not need to provide the tool that performs the harmful action; it may only need to influence how the synthetic subject uses a trusted tool.
This invocation creates an elevated exposure condition because trust boundaries between MCP servers may collapse inside the model context. A low-trust server may insert instructions that cause the synthetic subject to prefer, avoid, misuse, or reinterpret tools exposed by a separate trusted server.
The primary risk is cross-server influence. A malicious MCP server may shadow a trusted tool name, redefine expected behavior, inject instructions about another server’s tools, or cause sensitive data to be routed through the wrong tool. The operator may believe the synthetic subject is using an approved integration while its tool selection has been influenced by another server’s metadata.
Investigators should review MCP server inventories, tool namespaces, tool names, descriptions, schemas, server instructions, tool-list responses, connection order, and cross-server tool-call behavior. Particular attention should be given to duplicate tool names, instruction-bearing descriptions referring to other tools, newly connected servers, changed metadata, and tool calls whose selection does not match the operator’s request.
Investigative Relevance
Cross-server tool shadowing invocation is relevant because the effective instruction may originate from a different server than the tool ultimately used. The investigation must reconstruct the full MCP context, not only the tool that performed the final action.
This sub-section is especially relevant where synthetic subjects connect to multiple MCP servers, local developer tools, vendor connectors, marketplace servers, filesystem tools, communication tools, or mixed-trust tool registries.