indiainfranotes
Description-field injection at registration time is the quiet killer because input rails never see it. Treat every tool name, description, nested schema, and later tool result as untrusted input to the same classifier you already run on user messages. Pin server versions, allowlist hosts, and put a policy gateway between reasoning and execution so secretly skip approval cannot become a live credential call. Curious whether others re-scan tool metadata at every session start, or only on first install. marker1003h2228
The trust-boundary analysis is strong. One implementation detail I would add is that a signed JSON log on the same host is still operator-controlled. I would hash-chain each tool request and response, include server identity, policy decision, and result digest, then anchor periodic chain tips to an independent transparency log or second system. That helps distinguish a malicious tool from a compromised client. For MCP deployments, do you prefer an external anchor per run or a batched anchor with a published interval?