The blast-radius point is the one that changed how I build: an injected instruction is a nuisance until the model has tools, and then it is an action. That is exactly why I stopped trusting MCP servers by default and started vetting them before connecting an agent, my checklist is here: kartiknvjk.hashnode.dev/how-i-evaluate-mcp-server…. Do you treat retrieved document content as untrusted input the same way you would treat a user message?