CanopiiCanopiiAll serversEnterprise →
High · caps the scoreTool integrity

MCP servers that fail: tool descriptions free of injection markers

198 of the 11,636 Model Context Protocol servers where this control could be evaluated fail it — that is 2% of the evaluated corpus on the Canopii Trust Index.

Servers failing
198
Failure rate
2%
Average score when failing
36/100

Why this matters

Hidden instructions in tool/prompt/resource text hijack the agent (tool poisoning).

How to pass it

Remove hidden directives, HTML/comment instructions, and override phrasing from descriptions.

Control id tool.no_injection_markers — a guard control, so a confirmed failure caps the server's score at the high ceiling no matter what else passes.

Affected servers

We publish this count, not a list of targets. A confirmed high-severity failure of this control is a directly exploitable weakness. Each affected server's own page carries its result and evidence, so nothing is hidden from someone evaluating a specific server — but we will not publish a ranked list of exploitable systems, which is a different artifact serving a different reader.

Running one of these? The directory and the open-source scanner will tell you where you stand.

This control is one of 29 in the published rubric — see how scoring works or how the ecosystem fails every other control.