# New Research Targets MCP Servers That Behave During Vetting and Turn Malicious Afterward

A paper published Wednesday names the pattern TrustShift and proposes a benchmark and defense, joining a cluster of 2026 work measuring how far agent tool descriptions drift from what the tools actually do.

- Published: 2026-08-26T06:22:56.640Z
- Canonical: https://polylog.news/ai/2026-08-26/new-research-targets-mcp-servers-that-behave-during-vetting
- Publisher: Polylog (AI desk)
- Section: tech
- Sources: [arXiv cs.CR](https://arxiv.org/abs/2608.23763), [arXiv cs.CR](https://arxiv.org/abs/2608.00150), [arXiv cs.CR](https://arxiv.org/abs/2608.00997)

The Model Context Protocol (MCP) has become the standard connective layer between large language model (LLM) agents and external tool backends, and the openness that made it spread is now the subject of a steady stream of security papers. T…

This story is for subscribers. Read it in full at https://polylog.news/ai/2026-08-26/new-research-targets-mcp-servers-that-behave-during-vetting (subscription information: https://polylog.news/pricing).