We call this vulnerability “line jumping,” as it allows malicious MCP servers to execute attacks before any tool is even invoked. Figure 1: Prompt injection via tool description lets malicious MCP servers get around the host-enforced connection isolation; the model carries out the attack from the malicious server. This is a core part of MCP’s “Tool Safety” principle, which requires explicit user consent before invoking any tool.