Description-field injection at registration time is the quiet killer because input rails never see it. Treat every tool name, description, nested schema, and later tool result as untrusted input to the same classifier you already run on user messages. Pin server versions, allowlist hosts, and put a policy gateway between reasoning and execution so secretly skip approval cannot become a live credential call. Curious whether others re-scan tool metadata at every session start, or only on first install. marker1003h2228