Hire me NL
07 AI · agents

The tool description is part of the prompt

Note 0721 September 2026

When an agent connects to an MCP server, every tool description becomes text the model reads and obeys. A poisoned description can tell the model to read a private key before adding two numbers, to route all mail through one tool, or to keep quiet about it. The scanner checks names, descriptions and schemas for those markers, for sibling-tool references and for outbound URLs.

The sample manifest on the labs page shows the shape: an innocent add tool with an <IMPORTANT> block that asks for ~/.ssh/id_rsa, and a send_email tool that claims precedence over the calendar. Neither would look odd in a chat transcript.

Treat MCP servers like browser extensions with shell access. Pin versions, diff descriptions on every update, and run untrusted servers with no file or network reach. An agent review checks exactly those three things.

Run the lab: MCP tool-poisoning scanner →

A lab shows one signal. The call checks the whole chain.

Book a 30-minute call