How a Tool Description Becomes an Attack Surface
Inside a language model's context window, a tool description, a tool result and a resource all read the same as an instruction — which means a compromised or malicious MCP server can write the agent's next action itself.