Problems arising from the communication and data exchange between the LLM, Client, Server, and external systems/data.Description: Malicious instructions are injected into data that an MCP tool retrieves and then presents back to the LLM, causing the LLM to take unintended actions using other tools.Scanner Action: Very difficult for a server scanner alone. Analyze if tools fetch and process data from potentially untrusted external sources.Description: Exploiting vulnerabilities (like Tool Poisoning or Indirect Prompt Injection) to make the LLM misuse legitimate tools to send sensitive data to attacker-controlled destinations.Scanner Action: Analyze tool descriptions/code for patterns of accessing sensitive files/data AND sending data externally.Description: The core issue where the LLM, acting with the user's authority, is tricked by malicious input into performing harmful actions the user did not intend.Scanner Action: Not a specific vulnerability to scan *for*, but the *risk* that other vulnerabilities enable.